Known Vulnerabilities for Apache HttpClient by Apache Software Foundation
Listed below are 4 of the newest known vulnerabilities associated with "Apache HttpClient" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-71290 json | Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BU... | Not Provided | 2026-08-11 | 2026-08-13 |
| CVE-2026-64607 json | HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager... | Not Provided | 2026-07-31 | 2026-08-13 |
| CVE-2026-40542 json | Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-2... | Not Provided | 2026-04-22 | 2026-07-15 |
| CVE-2026-26214 json | Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS i... | Not Provided | 2026-02-12 | 2026-07-14 |