Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40542

Опубликовано: 22 апр. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

A flaw was found in Apache HttpClient. This vulnerability allows a remote attacker to bypass a critical step in the SCRAM-SHA-256 authentication process. By exploiting this, an attacker can trick the client into accepting authentication without proper mutual verification, potentially compromising the confidentiality and integrity of data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4httpclientNot affected
Migration Toolkit for Applications 8mta/mta-cli-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-java-external-provider-rhel9Not affected
OpenShift Developer Tools and ServicesjenkinsAffected
OpenShift Developer Tools and Servicesjenkins-2-pluginsAffected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-ddb-streams-source-rhel9Not affected
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-s3-sink-rhel9Not affected
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-s3-source-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-325
https://bugzilla.redhat.com/show_bug.cgi?id=2460518httpclient: Apache HttpClient: Authentication bypass due to missing mutual authentication verification

EPSS

Процентиль: 37%
0.00456
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
4 месяца назад

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

CVSS3: 7.3
nvd
4 месяца назад

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

CVSS3: 7.3
debian
4 месяца назад

Missing critical step in authentication in Apache HttpClient 5.6 allow ...

CVSS3: 7.3
github
4 месяца назад

Apache HttpClient accepts SCRAM-SHA-256 authentication without proper mutual authentication verification

EPSS

Процентиль: 37%
0.00456
Низкий

7.3 High

CVSS3