Skip to main content

Vendor/product archive

apache / httpclient CVEs

Beta · best-effort

8 CVEs tagged to apache / httpclient1 Critical, 2 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-40542

Published Apr 22, 2026

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication…

CVSS 7.3 · High
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2025-27820

Published Apr 24, 2025

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team.…

CVSS 7.5 · High
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2013-4366

Published Oct 30, 2017

http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-3577

Published Aug 21, 2014

org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname match…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5783

Published Nov 4, 2012

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain na…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1498

Published Jul 7, 2011

Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1