CVE-2026-40542

· NIST NVD ↗

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

HIGH
CVSS severity
7.3
CVSS base score
2026-04-22
Published

CWE codes

CWE-304

Affected products

apache:httpclient

Sources