PT-2026-70917 · Apache · Apache Httpcomponents Httpclient

·

CVE-2026-71290

·

Published

2026-08-11

·

Updated

2026-08-25

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache HttpComponents Client versions 5.4 through 5.6.3
Description An issue exists where the HostnameVerificationPolicy#BUILTIN setting is ignored when using the async version of HttpClient. This failure in TLS hostname verification allows an attacker capable of intercepting and modifying traffic between the client and the server to impersonate the server by presenting a valid certificate issued for a different domain.
Recommendations Upgrade to version 5.6.4 or newer.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71290

Affected Products

Apache Httpcomponents Httpclient