CVE-2026-40542
Received
Received - Intake
Authentication Bypass in Apache HttpClient 5.6 via SCRAM-SHA
Publication date: 2026-04-22
Last updated on: 2026-05-01
Assigner: Apache Software Foundation
Description
Description
Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apache | httpclient | 5.6 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-304 | The product implements an authentication technique, but it skips a step that weakens the technique. |