Do you want disclose a potential security issue for Apache HttpComponents? Send your report to the Apache Security Team.
You can read more about the security policy on:
This section is experimental: it provides advisories since 2023 and may lag behind the official CVE publications. It may also lack details found on the project security page linked above. If you have any feedback on how you would like this data to be provided, you are welcome to reach out on our public mailinglist or privately on security@apache.org {.bg-warning}
CVE-2026-64607 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-31T10:12:13.331Z
CVE-2026-54428 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-01T17:05:28.114Z
Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.
CVE-2026-54399 [CVE] [CVE json] [OSV json]
Last updated: 2026-07-01T17:05:54.930Z
CVE-2026-40542 [CVE] [CVE json] [OSV json]
Last updated: 2026-04-22T07:07:19.055Z
Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.
CVE-2025-27820 [CVE] [CVE json] [OSV json]
Last updated: 2025-06-04T11:19:13.066Z
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release