Httpclient
Vendor:
First CVE: Jul 7, 2011 · Active for 15 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Httpclient over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2011
15 years ago
Most Recent CVE
Apr 22, 2026
93 days ago
CVE Severity & Scoring
Httpclient8 CVEs
63%
25%
13%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (50.0%)
Unknown4 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (50.0%)
High0 (0.0%)
Unknown4 (50.0%)
User Interaction
None4 (50.0%)
Unknown4 (50.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (50.0%)
Unknown4 (50.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40542HIGH Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication | Apr 22, 2026 | 7.3 | 29 | NO | NO |
CVE-2012-5783MEDIUM Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain nam | Nov 4, 2012 | 5.8 | 25 | NO | NO |
CVE-2013-4366CRITICAL http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified im | Oct 30, 2017 | 9.8 | 24 | NO | NO |
CVE-2025-27820HIGH A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. F | Apr 24, 2025 | 7.5 | 23 | NO | NO |
CVE-2020-13956MEDIUM Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick th | Dec 2, 2020 | 5.3 | 20 | NO | NO |
CVE-2015-5262MEDIUM http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which | Oct 27, 2015 | 4.3 | 20 | NO | NO |
CVE-2014-3577MEDIUM org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matche | Aug 21, 2014 | 5.8 | 20 | NO | NO |
CVE-2011-1498MEDIUM Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows | Jul 7, 2011 | 4.3 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Httpclient
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.6 | 1 | 7.3 | 0.5% | 0 | 0 |
| 4.3 | 1 | 9.8 | 2.2% | 0 | 0 |
| 4.1 | 1 | 4.3 | 6.7% | 0 | 0 |
| 4.0.1 | 1 | 4.3 | 6.7% | 0 | 0 |
| 4.0 | 1 | 4.3 | 6.7% | 0 | 0 |
| 3.1 | 1 | 5.8 | 9.3% | 0 | 0 |