Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v468-qcjx-r72w | Apache HttpClient accepts SCRAM-SHA-256 authentication without proper mutual authentication verification |
Tue, 05 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-325 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 01 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:httpclient:5.6:-:*:*:*:*:*:* |
Wed, 22 Apr 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 22 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 22 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache httpclient |
|
| Vendors & Products |
Apache
Apache httpclient |
Wed, 22 Apr 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue. | |
| Title | Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification | |
| Weaknesses | CWE-304 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-04-22T16:23:59.296Z
Reserved: 2026-04-14T09:11:14.268Z
Link: CVE-2026-40542
Updated: 2026-04-22T16:23:59.296Z
Status : Analyzed
Published: 2026-04-22T08:16:12.780
Modified: 2026-05-01T17:12:59.940
Link: CVE-2026-40542
OpenCVE Enrichment
Updated: 2026-05-05T01:30:12Z
Github GHSA