VendorsApachehttpclientall versions
Vulnerabilities

Apache Software Foundation HttpClient

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2013-4366
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
Published 2017-10-30 · Modified
9.8EPSS 0.033
CVE-2026-71290
Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
Published 2026-08-11 · Analyzed
9.1EPSS 0.003
CVE-2025-27820
Apache HttpComponents: PSL (Public Suffix List) validation bypass
Published 2025-04-24 · Analyzed
7.5EPSS 0.010
CVE-2026-40542
Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification
Published 2026-04-22 · Modified
7.3EPSS 0.007
CVE-2012-5783
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published 2012-11-04 · Modified
5.8EPSS 0.093
CVE-2014-3577
org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the "foo,CN=www.apache.org" string in the O field.
Published 2014-08-21 · Modified
5.8EPSS 0.091
CVE-2020-13956
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
Published 2020-12-02 · Modified
5.3EPSS 0.090
CVE-2026-64607
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Published 2026-07-31 · Modified
5.3EPSS 0.006
CVE-2015-5262
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
Published 2015-10-27 · Modified
4.3EPSS 0.188
CVE-2011-1498
Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
Published 2011-07-07 · Modified
4.3EPSS 0.067