CVE-2026-71290Disclosure(apache / httpclient)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache httpclient systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • httpclient

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 2 mentions (2026-08-18); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
httpclient

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-08-18: 2Mentions · 2026-08-19: 2Mentions · 2026-08-25: 1Mentions · 2026-08-27: 1Patch / Workaround · 2026-08-18: 2Patch / Workaround · 2026-08-19: 1Patch / Workaround · 2026-08-25: 1Patch / Workaround · 2026-08-27: 1Technical Details · 2026-08-18: 2Technical Details · 2026-08-19: 2Technical Details · 2026-08-25: 1Technical Details · 2026-08-27: 108-1808-1908-2508-27
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-182
Disclosure1Patch1
2026-08-192
Disclosure2
2026-08-251
Patch1
2026-08-271
Disclosure1
Full discourse6 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    CVE-2026-71290 (CVSS 9.1) is an Apache HttpClient TLS vulnerability that lets attackers intercept and modify traffic via MITM attacks. Update to 5.6.4. #ApacheHttpClient #CVE202671290 #MITM #InfoSec https://securityonline.info/apache-httpclient-cve-2026-71290/

    Post summary

    Apache HttpClient TLS vulnerability CVE-2026-71290 is disclosed with CVSS 9.1, and users are advised to update to version 5.6.4 to mitigate the risk.

    02151550
    13.0K followersView on X
  • yousukezan@yousukezan
    Disclosure

    Apache HttpComponents Clientで2件の脆弱性が公開された。CVE-2026-71290では非同期トランスポートのTLSホスト名検証が無効化され、中間者攻撃で別ドメイン用の証明書でも接続が成立する。CVE-2026-64607では接続プール枯渇が発生する。 CVE-2026-71290は5.4-alphaから5.6.3までの非同期トランスポートに影響し、HostnameVerificationPolicyを有効にしていても要求先ホスト名と証明書の一致を確認しない。クラシックトランスポートは影響を受けない。CVE-2026-64607は5.0-alpha1から5.6.2までのクラシッククライアントに影響し、不正なContent-Encodingヘッダーを含む応答で接続が解放されず、最終的にプールを使い果たす。Apache HttpComponents Client 5.6.4では両問題の影響範囲を外れる。記事執筆時点で、いずれの脆弱性についても公開された悪用事例は確認されていない。 https://securityonline.info/apache-httpclient-cve-2026-71290/

    Post summary

    The article announces two CVEs affecting Apache HttpComponents Client, details their technical impact, notes no active exploitation, and indicates that version 5.6.4 no longer suffers from the issues.

    000011.2K
    14.8K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Apache HttpComponents Client の脆弱性 CVE-2026-71290 が FIX:中間者攻撃の恐れ https://iototsecnews.jp/2026/08/19/critical-apache-httpcomponents-client-flaw-lets-attackers-impersonate-servers/ Apache HttpComponents Client の非同期通信において、TLS ホスト名検証が正常に機能しないという不具合が確認されました。通信経路上の第三者による送信データの不法解読 / API レスポンスの改ざん / 認証情報の不正取得といった重大な被害につながる恐れがあります。この脆弱性は CVE-2026-71290 として管理されています。影響を受ける環境の特定および Apache HttpComponents Client 5.6.4 以降への速やかなアップデートが求められます。 #Apache #CVE202671290 #HttpComponentsClient #Vulnerability

    Post summary

    Apache HttpComponents Client suffers from a TLS hostname verification flaw (CVE‑2026‑71290) that could enable MITM attacks; vendors are urged to update to version 5.6.4 or newer.

    0000078
    510 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    New Apache HttpComponents Client TLS bypass (CVE-2026-71290) enables MitM, severely compromising data privacy & integrity in transit. Patch immediately! (Aug 24, 2026) #Cybersecurity #Vulnerabilities #News

    Post summary

    The tweet announces the discovery of CVE-2026-71290, a TLS bypass in Apache HttpComponents Client that permits MITM attacks, and urges immediate patching.

    0000046
    17 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    CyberSignal Daily ✓ · 🔐 Application Security · August 19, 2026 🎯 Encryption isn't enough if software verifies the wrong server. August 19 coverage highlights CVE-2026-71290, a critical vulnerability in Apache HttpComponents Client involving improper TLS hostname verification. Under vulnerable configurations, an attacker in a suitable network position could potentially impersonate a trusted server despite the connection using TLS. CISA/NVD enrichment currently indicates no known exploitation, while patched releases are available. 🔗 Sources: Apache / NVD / GBHackers #Apache #TLS #CVE #AppSec #Java #CyberSecurity

    Post summary

    The post announces CVE-2026-71290, a critical TLS hostname verification flaw in Apache HttpComponents Client, and notes that vendor patches are available.

    0000032
    82 followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-71290:Apache HttpClientの脆弱性により、攻撃者がトラフィックを傍受および改ざんできる(CVSS 9.1) CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1) #DailyCyberSecurity (Aug 18) https://securityonline.info/apache-httpclient-cve-2026-71290/

    Post summary

    The post announces CVE-2026-71290, a high‑severity Apache HttpClient flaw that permits traffic interception and modification, with a CVSS 9.1 rating.

    00000285
    4.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttpclient---

Explore more