Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223832 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-71290PATCHED
apache · httpclient

Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)

Description

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

Affected Products

VendorProductVersions
apachehttpclient5.4-alpha

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apachehttpcomponentscert_advisory90%
oraclecommunicationscert_advisory90%

References

  • https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq(vendor-advisory)

Related News (6 articles)

Tier B
CERT-FR3d ago
Multiples vulnérabilités dans les produits IBM (25 septembre 2026)
→ No new info (linked only)
Tier B
BSI Advisories11d ago
[NEU] [hoch] Oracle Communications: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits IBM (11 septembre 2026)
→ No new info (linked only)
Tier C
oss-security45d ago
CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
→ No new info (linked only)
Tier B
BSI Advisories46d ago
[NEU] [mittel] Apache HttpComponents: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
→ No new info (linked only)
Tier C
VulDB47d ago
CVE-2026-71290 | Apache HttpComponents Client up to 5.6.3 Async HttpClient HostnameVerificationPolicy#BUILTIN certificate validation
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://lists.apache.org/thread/bhf7g2zwpom2ohvwjjjlonc93br2s8vq
CWECWE-295
PublishedAug 11, 2026
Trending Score45
Source articles6
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-59878
Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
Trending: 39
CRITICALCVE-2026-55976
Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation on avro.schema.url
Trending: 33
CRITICALCVE-2026-49845
Apache Hive: SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL paths
Trending: 27
CRITICALCVE-2026-66713
Apache Axis2/Java: deserialization of untrusted Data
Trending: 21
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 19

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026
Patch Available
Sep 24, 2026