VendorsApachehttpclientany version
Vulnerabilities

Apache Software Foundation HttpClient any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-71290
Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
Published 2026-08-11 · Analyzed
9.1EPSS 0.003
CVE-2025-27820
Apache HttpComponents: PSL (Public Suffix List) validation bypass
Published 2025-04-24 · Analyzed
7.5EPSS 0.010
CVE-2014-3577
org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the "foo,CN=www.apache.org" string in the O field.
Published 2014-08-21 · Modified
5.8EPSS 0.091
CVE-2020-13956
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
Published 2020-12-02 · Modified
5.3EPSS 0.090
CVE-2026-64607
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Published 2026-07-31 · Modified
5.3EPSS 0.006
CVE-2015-5262
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
Published 2015-10-27 · Modified
4.3EPSS 0.188