CVE-2026-71290
CVE-2026-71290 is a critical-severity vulnerability in Apache Httpclient with a CVSS 3.x base score of 9.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-295.
Key facts
- Severity: Critical (CVSS 3.x base score 9.1)
- EPSS exploit prediction: 0% (9th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-295
- Affected product: Apache Httpclient
- Published:
- Last modified:
Description
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. Please note the classic version of HttpClient is not affected by this vulnerability. Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.
Frequently asked questions
- What is CVE-2026-71290?
- Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. Please note the classic version of HttpClient is not affected by this vulnerability. Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.
- How severe is CVE-2026-71290?
- CVE-2026-71290 has a CVSS 3.x base score of 9.1, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-71290 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (9th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-71290?
- CVE-2026-71290 affects Apache Httpclient. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-71290?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-71290 published?
- CVE-2026-71290 was published on 2026-08-11 and last updated on 2026-08-17.
References
- https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq
- http://www.openwall.com/lists/oss-security/2026/08/13/6
Affected products (1)
- cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*
More vulnerabilities in Apache Httpclient
- CVE-2013-4366 — Critical (CVSS 9.8): http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that…
- CVE-2025-27820 — High (CVSS 7.5): A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host…
- CVE-2026-40542 — High (CVSS 7.3): Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept…
- CVE-2014-3577 — Medium (CVSS 5.8): org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before…
- CVE-2012-5783 — Medium (CVSS 5.8): Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products,…
- CVE-2026-64607 — Medium (CVSS 5.3): HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection…
All CVEs affecting Apache Httpclient →
Other CWE-295 (Improper Certificate Validation) vulnerabilities
- CVE-2026-58162 — Critical (CVSS 10.0): The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue…
- CVE-2026-4370 — Critical (CVSS 10.0): A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the…
- CVE-2026-30836 — Critical (CVSS 10.0): Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6…
- CVE-2025-68121 — Critical (CVSS 10.0): During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between…
- CVE-2022-20703 — Critical (CVSS 10.0): Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker…
- CVE-2021-1471 — Critical (CVSS 9.9): Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms…
Browse all CWE-295 (Improper Certificate Validation) vulnerabilities →