What is CVE-2026-71290?
This vulnerability in Apache HttpComponents Client 5.4 and newer involves improper TLS hostname verification. Since the HostnameVerificationPolicy#BUILTIN setting is ineffective with the async HttpClient, an attacker intercepting traffic can impersonate the server. Affected systems should be patched immediately or use alternative verification mechanisms.
Azərbaycanca: Bu boşluq Apache HttpComponents Client-in 5.4 və daha yeni versiyalarında TLS hostname doğrulamasının düzgün işləməməsi ilə bağlıdır. Asinxron HttpClient ilə HostnameVerificationPolicy#BUILTIN parametri təsirsiz olduğu üçün şəbəkə trafikini ələ keçirən şəxs serveri təqlid edə bilər. Təsirə məruz qalan sistemlərdə təcili olaraq yamaq tətbiq edilməli və ya alternativ doğrulama mexanizmləri istifadə olunmalıdır.
Related CVEs
link basis: shared vendor: Apache
FAQ2
Which versions of Apache HttpComponents Client are affected by CVE-2026-71290?
This vulnerability affects Apache HttpComponents Client version 5.4 and newer.
Why is the HostnameVerificationPolicy#BUILTIN setting ineffective in CVE-2026-71290?
The HostnameVerificationPolicy#BUILTIN setting is ineffective when used with the async HttpClient, causing improper TLS hostname verification.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.