THREATOPS
THREAT OPSThreat News › CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)

CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)

medoss_secPublished 2026-08-13

<p>Posted by Oleg Kalnichevski on Aug 13</p>Severity: important <br /> <br /> Affected versions:<br /> <br /> - Apache HttpComponents Client (org.apache.httpcomponents.client5:httpclient5) 5.4-alpha through 5.6.3<br /> <br /> Description:<br /> <br /> Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. <br /> HostnameVerificationPolicy#BUILTIN setting has

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/481