CVE-2026-40542
EUVD-2026-2463022.04.2026, 08:16
Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | httpclient | 5.6 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration
- CWE-304 - Missing Critical Step in AuthenticationThe software implements an authentication technique, but it skips a step that weakens the technique.
- CWE-325 - Missing Cryptographic StepThe product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.
References