CVE-2026-40542
EUVD-2026-2463022.04.2026, 08:16
Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | httpclient | 5.6 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | OpenShift Developer Tools and Services 4.12 | 1786628667 ≤ 𝑥 < * | ADP |
| Red Hat | OpenShift Developer Tools and Services 4.13 | 1786628681 ≤ 𝑥 < * | ADP |
| Red Hat | OpenShift Developer Tools and Services 4.14 | 1786533561 ≤ 𝑥 < * | ADP |
| Red Hat | OpenShift Developer Tools and Services 4.15 | 1786533565 ≤ 𝑥 < * | ADP |
| Red Hat | OpenShift Developer Tools and Services 4.16 | 1787125166 ≤ 𝑥 < * | ADP |
| Red Hat | OpenShift Developer Tools and Services 4.17 | 1787124635 ≤ 𝑥 < * | ADP |
| Red Hat | OpenShift Developer Tools and Services 4.18 | 1787125069 ≤ 𝑥 < * | ADP |
| Red Hat | OpenShift Developer Tools and Services 4.19 | 1787124632 ≤ 𝑥 < * | ADP |
| Red Hat | OpenShift Developer Tools and Services 4.20 | 1787124925 ≤ 𝑥 < * | ADP |
| Red Hat | OpenShift Developer Tools and Services 4.21 | 1787125311 ≤ 𝑥 < * | ADP |
| Red Hat | OpenShift Developer Tools and Services 4.22 | 1787124779 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
- CWE-304 - Missing Critical Step in AuthenticationThe software implements an authentication technique, but it skips a step that weakens the technique.
- CWE-325 - Missing Cryptographic StepThe product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.
References