CVE-2026-40542
Published Apr 22, 2026Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication…
- evidence mentions
- 5
- Buzz score
- 32.4