CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)

Posted by Oleg Kalnichevski on Aug 13

Severity: important

Affected versions:

- Apache HttpComponents Client (org.apache.httpcomponents.client5:httpclient5) 5.4-alpha through 5.6.3

Description:

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer.
HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker
that can intercept and modify traffic between the client and the server can...

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论