Improper TLS Hostname Verification in Apache HttpComponents Client
CVE-2026-71290
Currently unrated
What is CVE-2026-71290?
An improper TLS hostname verification vulnerability exists in Apache HttpComponents Client version 5.4 and later. When using the async option of HttpClient, the built-in hostname verification policy does not function as intended. This misconfiguration allows an attacker capable of intercepting and altering traffic between the client and server to impersonate the server by utilizing a valid certificate for a domain that differs from the intended server's domain. Users are encouraged to update to version 5.6.4 or newer to mitigate this risk.
Affected Version(s)
Apache HttpComponents Client 5.4-alpha <= 5.6.3