Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-71290

Опубликовано: 11 авг. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. 

Please note the classic version of HttpClient is not affected by this vulnerability. 

Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*
Версия от 5.4 (включая) до 5.6.4 (исключая)

EPSS

Процентиль: 15%
0.00242
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 9.1
ubuntu
20 дней назад

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. Please note the classic version of HttpClient is not affected by this vulnerability. Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

CVSS3: 8.1
redhat
20 дней назад

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

CVSS3: 9.1
debian
20 дней назад

Improper TLS hostname verification vulnerability in Apache HttpCompone ...

CVSS3: 9.1
github
20 дней назад

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

EPSS

Процентиль: 15%
0.00242
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-295