A critical vulnerability in the Apache HttpComponents Client can allow man-in-the-middle attackers to impersonate trusted servers when applications use the asynchronous version of HttpClient. This vulnerability is tracked as CVE-2026-71290 and arises from improper TLS hostname verification in Apache HttpComponents Client versions 5.4 through 5.6.3. Apache HttpComponents Client Flaw The issue specifically affects applications configured […]
Read the original article: