Critical Authentication Bypass in Apache HttpClient 5.6
ID: 50127801-a442-5c76-bdb5-8d2494ac1300
STIX ID: report--50127801-a442-5c76-bdb5-8d2494ac1300
Feed Name: securityonline.info
Threat Score
The Apache Software Foundation warned of CVE-2026-40542 in Apache HttpClient 5.6: a missing verification during SCRAM-SHA-256 mutual authentication can let attackers impersonate servers and cause clients to accept insecure connections. Apache released a fix and users are urged to upgrade to HttpClient 5.6.1 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
