CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
Posted by Oleg Kalnichevski on Aug 13
Severity: important
Affected versions:
- Apache HttpComponents Client (org.apache.httpcomponents.client5:httpclient5) 5.4-alpha through 5.6.3
Description:
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer.
HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker
that can intercept and modify traffic between the client and the server can...
评论
?
参与讨论