Improper TLS Hostname Verification in Apache HttpComponents Client
CVE-2026-71290

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
11 August 2026

What is CVE-2026-71290?

An improper TLS hostname verification vulnerability exists in Apache HttpComponents Client version 5.4 and later. When using the async option of HttpClient, the built-in hostname verification policy does not function as intended. This misconfiguration allows an attacker capable of intercepting and altering traffic between the client and server to impersonate the server by utilizing a valid certificate for a domain that differs from the intended server's domain. Users are encouraged to update to version 5.6.4 or newer to mitigate this risk.

Affected Version(s)

Apache HttpComponents Client 5.4-alpha <= 5.6.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.