cbcvebase.
CVE-2026-40542
published 2026-04-22

CVE-2026-40542: Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper…

high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttpclient
apachehttpclient
apache_software_foundationapache_httpclient>= 5.6 < 5.6.15.6.1
candlepinprojectcandlepin
debiandogtag-pki
debianpuppetserver
devspacesopenvsx-rhel9
devspacespluginregistry-rhel9
javapackages-tools_201801httpcomponents-client
javapackages-tools_201801maven-doxia
javapackages-tools_201801maven-resolver
javapackages-tools_201801maven-wagon
jenkinsjenkins
maven_3.9httpcomponents-client
maven_3.9maven
maven_3.9maven-resolver
maven_3.9maven-wagon
mtamta-cli-rhel9
mtamta-java-external-provider-rhel9
ocp-tools-4jenkins-rhel8
ocp-tools-4jenkins-rhel9
offline-knowledge-portalrhokp-rhel9
openshift-serverless-1kn-eventing-integrations-aws-ddb-streams-source-rhel9
openshift-serverless-1kn-eventing-integrations-aws-s3-sink-rhel9
openshift-serverless-1kn-eventing-integrations-aws-s3-source-rhel9