Bug 2514394 (CVE-2026-71290)

Summary: CVE-2026-71290 org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: ant, avibelli, bgeorges, ccranfor, cescoffi, cmah, dandread, dhanak, dkreling, drosa, dsimansk, ewittman, fmariani, fmongiar, gmalinko, gsmet, janstey, jmartisk, jnethert, jpechane, jwon, kaycoth, kingland, lthon, manderse, mcarlett, mnovotny, mosmerov, nipatil, olubyans, pantinor, pesilva, pgallagh, pjindal, probinso, rguimara, rhel-process-autobot, rkubis, rruss, rstepani, rsvoboda, sausingh, sbiarozk, sdawley, tcunning, tqvarnst, watson-tool-maintainers, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the asynchronous version of Apache HttpComponents Client. This improper Transport Layer Security (TLS) hostname verification vulnerability allows a remote attacker to intercept and modify network traffic. By presenting a valid certificate for a different domain, an attacker can impersonate the server, leading to a Man-in-the-Middle (MITM) attack and compromising communication.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-11 20:51:23 UTC
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and
 the server can impersonate the server by presenting a valid certificate
 for a different domain. 


Please note the classic version of HttpClient is not affected by this vulnerability. 

Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

Comment 1 errata-xmlrpc 2026-09-03 18:34:26 UTC
This issue has been addressed in the following products:

  Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.3.SP1

Via RHSA-2026:63302 https://access.redhat.com/errata/RHSA-2026:63302