{"id":"GHSA-v468-qcjx-r72w","summary":"Apache HttpClient accepts SCRAM-SHA-256 authentication without proper mutual authentication verification","details":"Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.","aliases":["CVE-2026-40542"],"modified":"2026-07-17T21:06:49.649947376Z","published":"2026-04-22T09:31:31Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-29T20:52:54Z","nvd_published_at":"2026-04-22T08:16:12Z","cwe_ids":["CWE-304"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40542"},{"type":"WEB","url":"https://github.com/apache/httpcomponents-client/commit/726eac2323d370435d8afca1e0540aa099927f18"},{"type":"PACKAGE","url":"https://github.com/apache/httpcomponents-client"},{"type":"WEB","url":"https://lists.apache.org/thread/tfmgv86xr0z1y096vs3z0y315t1v3o97"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/04/22/5"}],"affected":[{"package":{"name":"org.apache.httpcomponents.client5:httpclient5","ecosystem":"Maven","purl":"pkg:maven/org.apache.httpcomponents.client5/httpclient5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.6-alpha1"},{"fixed":"5.6.1"}]}],"versions":["5.6","5.6-alpha1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-v468-qcjx-r72w/GHSA-v468-qcjx-r72w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}