CVE-2026-71290

CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)

Vendor Apache Software Foundation
Product Apache HttpComponents Client
Weakness CWE-295
Published August 11, 2026
Last update August 13, 2026

CVSS base score

What the vulnerability does

01Description

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.  Please note the classic version of HttpClient is not affected by this vulnerability.  Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

Key dates

02Disclosure timeline

August 11, 2026 CVE published
August 13, 2026 Record updated