THREAT OPS › Threat News › CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
<p>Posted by Oleg Kalnichevski on Aug 13</p>Severity: important <br /> <br /> Affected versions:<br /> <br /> - Apache HttpComponents Client (org.apache.httpcomponents.client5:httpclient5) 5.4-alpha through 5.6.3<br /> <br /> Description:<br /> <br /> Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. <br /> HostnameVerificationPolicy#BUILTIN setting has
Indicators of compromise
- CVE-2026-71290cve
Original source: https://seclists.org/oss-sec/2026/q3/481