Known vulnerabilities in Apache HttpComponents Client
Vendor:
Apache Foundation
Software:
Apache HttpComponents Client
Software CPE:
cpe:2.3:a:apache_foundation:httpcomponents-client:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
5.6.4
5.6.3
5.6.2
5.6.1
5.6
5.5.2
5.5.1
5.5
5.4.4
5.4.3
5.4.2
5.4.1
5.4
5.3.1
5.3
5.2.3
5.2.2
5.2.1
4.5.14
5.1.4
5.2
5.1.3
5.1.2
5.1.1
5.1
5.0.4
5.0.3
5.0.2
5.0.1
5.0
4.5.13
4.5.12
4.5.11
4.5.10
4.5.9
4.5.8
4.5.7
4.5.6
4.5.5
4.5.4
4.5.3
4.5.2
4.5.1
4.5
4.4.1
4.4
4.3.6
4.3.5
4.3.4
4.3.3
4.3.2
4.3.1
4.3
4.2.6
4.2.5
4.2.4
4.2.3
4.2.2
4.2.1
4.2
4.1.3
4.1.2
4.1.1
4.1
4.0.3
4.0.2
4.0.1
4.0
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU144886 - Improper Validation of Certificate with Host Mismatch CVE-2026-71290 |
CWE-297 | High | 5.6.4 | 24.08.2026 |
SB20260824163 SB2026090730 SB2026091582 and 2 more |
||
| #VU144885 - Missing Release of Resource after Effective Lifetime CVE-2026-64607 |
CWE-772 | Medium | 5.6.3 | 24.08.2026 |
SB20260824161 SB2026090730 SB2026090780 and 2 more |
||
| #VU57150 - Improper Certificate Validation CVE-2014-3577 |
CWE-295 | Low | 4.3.5 | 08.10.2021 |
SB2014082106 SB2021100807 SB2023020872 and 24 more |