Known vulnerabilities in Apache HttpComponents Client

Software CPE: cpe:2.3:a:apache_foundation:httpcomponents-client:*:*:*:*:*:*:*:*
Total vulnerabilities: 3
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache HttpComponents Client Apache HttpComponents Client is affected by 3 known vulnerabilities: 1 high, 1 medium, 1 low Critical High Medium Low

Vulnerabilities (3)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144886 - Improper Validation of Certificate with Host Mismatch
CVE-2026-71290
CWE-297 High
No
No
5.6.4 24.08.2026 SB20260824163
SB2026090730
SB2026091582
and 2 more
#VU144885 - Missing Release of Resource after Effective Lifetime
CVE-2026-64607
CWE-772 Medium
No
No
5.6.3 24.08.2026 SB20260824161
SB2026090730
SB2026090780
and 2 more
#VU57150 - Improper Certificate Validation
CVE-2014-3577
CWE-295 Low
No
No
4.3.5 08.10.2021 SB2014082106
SB2021100807
SB2023020872
and 24 more