PT-2026-34264 · Apache · Apache Httpclient

Rasmus Moorats

·

Published

2026-04-22

·

Updated

2026-04-22

·

CVE-2026-40542

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

Weakness Enumeration

Related Identifiers

CVE-2026-40542

Affected Products

Apache Httpclient