Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40542

Опубликовано: 22 апр. 2026
Источник: debian
EPSS Низкий

Описание

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
httpcomponents-clientnot-affectedpackage

Примечания

  • https://lists.apache.org/thread/tfmgv86xr0z1y096vs3z0y315t1v3o97

  • Fixed by: https://github.com/apache/httpcomponents-client/commit/1acf00b879d908a869508ceee2edb0fe65b69d73 (rel/5.6.1, 5.6.1-RC1)

EPSS

Процентиль: 37%
0.00456
Низкий

Связанные уязвимости

CVSS3: 7.3
ubuntu
4 месяца назад

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

CVSS3: 7.3
redhat
4 месяца назад

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

CVSS3: 7.3
nvd
4 месяца назад

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

CVSS3: 7.3
github
4 месяца назад

Apache HttpClient accepts SCRAM-SHA-256 authentication without proper mutual authentication verification

EPSS

Процентиль: 37%
0.00456
Низкий