logo

Critical Authentication Bypass in Apache HttpClient 5.6

ID: 50127801-a442-5c76-bdb5-8d2494ac1300

STIX ID: report--50127801-a442-5c76-bdb5-8d2494ac1300

Feed Name: securityonline.info

Threat Score
60/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Ddos

...
...

The Apache Software Foundation warned of CVE-2026-40542 in Apache HttpClient 5.6: a missing verification during SCRAM-SHA-256 mutual authentication can let attackers impersonate servers and cause clients to accept insecure connections. Apache released a fix and users are urged to upgrade to HttpClient 5.6.1 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.