Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71290

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

A flaw was found in the asynchronous version of Apache HttpComponents Client. This improper Transport Layer Security (TLS) hostname verification vulnerability allows a remote attacker to intercept and modify network traffic. By presenting a valid certificate for a different domain, an attacker can impersonate the server, leading to a Man-in-the-Middle (MITM) attack and compromising communication.

Отчет

This vulnerability is rated as Important as it allows for server impersonation in Red Hat products utilizing the asynchronous Apache HttpComponents Client. An attacker positioned to intercept and alter network traffic can present a fraudulent server certificate, bypassing TLS hostname verification and potentially leading to man-in-the-middle attacks. This flaw does not affect the classic version of HttpClient.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and Servicesjenkins-2-pluginsNot affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Not affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Not affected
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-ddb-streams-source-rhel9Under investigation
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-s3-sink-rhel9Under investigation
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-s3-source-rhel9Under investigation
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-sns-sink-rhel9Under investigation
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-sqs-sink-rhel9Under investigation
OpenShift Serverlessopenshift-serverless-1/kn-eventing-integrations-aws-sqs-source-rhel9Under investigation
Red Hat build of Apache Camel 4 for Quarkus 3camel-quarkus-support-httpclient5Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2514394org.apache.httpcomponents/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification

EPSS

Процентиль: 15%
0.00242
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
20 дней назад

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. Please note the classic version of HttpClient is not affected by this vulnerability. Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

CVSS3: 9.1
nvd
20 дней назад

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

CVSS3: 9.1
debian
20 дней назад

Improper TLS hostname verification vulnerability in Apache HttpCompone ...

CVSS3: 9.1
github
20 дней назад

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

EPSS

Процентиль: 15%
0.00242
Низкий

8.1 High

CVSS3