CVE-2026-40542
Apache Software Foundation Apache HttpClient, Cryostat 4, Migration Toolkit for Applications 8
Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.
- CVSS
- 7.3
- EPSS
- 0.46% 37.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.22