Known Vulnerabilities for Httpclient by Apache
Listed below are 6 of the newest known vulnerabilities associated with "Httpclient" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40542 json | Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-2... | Not Provided | 2026-04-22 | 2026-04-22 |
| CVE-2020-13956 json | Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs p... | 5.3 - MEDIUM | 2020-12-02 | 2023-11-07 |
| CVE-2015-5262 json | http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeou... | 4.3 - MEDIUM | 2015-10-27 | 2023-02-13 |
| CVE-2014-3577 json | org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 d... | 5.8 - MEDIUM | 2014-08-21 | 2023-11-07 |
| CVE-2013-4366 json | http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is ... | 9.8 - CRITICAL | 2017-10-30 | 2020-07-28 |
| CVE-2012-5783 json | Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does n... | 5.8 - MEDIUM | 2012-11-04 | 2021-04-23 |
| CVE-2011-1498 json | Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-A... | 4.3 - MEDIUM | 2011-07-07 | 2011-09-22 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Httpclient | 5.0.3 | |||
| Application | Apache | Httpclient | 5.0.2 | |||
| Application | Apache | Httpclient | 5.0.1 | |||
| Application | Apache | Httpclient | 5.0.0 | |||
| Application | Apache | Httpclient | 5.0.0 | |||
| Application | Apache | Httpclient | 5.0.0 | |||
| Application | Apache | Httpclient | 5.0.0 | |||
| Application | Apache | Httpclient | 5.0.0 | |||
| Application | Apache | Httpclient | 5.0.0 | |||
| Application | Apache | Httpclient | 5.0.0 | |||
| Application | Apache | Httpclient | 5.0.0 | |||
| Application | Apache | Httpclient | 5.0.0 | |||
| Application | Apache | Httpclient | 5.0.0 | |||
| Application | Apache | Httpclient | 5.0.0 | |||
| Application | Apache | Httpclient | 4.5.9 | |||
| Application | Apache | Httpclient | 4.5.8 | |||
| Application | Apache | Httpclient | 4.5.7 | |||
| Application | Apache | Httpclient | 4.5.6 | |||
| Application | Apache | Httpclient | 4.5.5 | |||
| Application | Apache | Httpclient | 4.5.4 |