Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-40542

Опубликовано: 22 апр. 2026
Источник: nvd
CVSS3: 7.3
EPSS Низкий

Описание

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:httpclient:5.6:-:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00456
Низкий

7.3 High

CVSS3

Дефекты

CWE-304
CWE-325

Связанные уязвимости

CVSS3: 7.3
ubuntu
4 месяца назад

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

CVSS3: 7.3
redhat
4 месяца назад

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

CVSS3: 7.3
debian
4 месяца назад

Missing critical step in authentication in Apache HttpClient 5.6 allow ...

CVSS3: 7.3
github
4 месяца назад

Apache HttpClient accepts SCRAM-SHA-256 authentication without proper mutual authentication verification

EPSS

Процентиль: 37%
0.00456
Низкий

7.3 High

CVSS3

Дефекты

CWE-304
CWE-325