VDB

CVE-2026-71290

CVE-2026-71290 PUBLISHED CVSS 9.1 CRITICAL

Reported by apache · Published August 11, 2026

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

Risk Scores

CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Apache Software FoundationApache HttpComponents Client5.4-alpha
chainguardlogstash-8.190
Apache Software FoundationApache HttpComponents Client5.4-alpha, 5.4-alpha, 5.4-alpha

Timeline

  • Aug 11, 2026 CVE Published
  • Aug 12, 2026 Coalition ESS Score
  • Aug 15, 2026 Security Advisory
  • Aug 17, 2026 CVE Updated
  • Aug 24, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 4, 2026 Distribution Patch
  • Sep 4, 2026 Security Advisory
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›