Intel

AIKIDO-2026-10647

httpclient5 is vulnerable to Missing Critical Step in Authentication

Missing Critical Step in AuthenticationCVE-2026-40542 Published Apr 29, 2026

75

High Risk

This Affects:

javahttpclient5
5.6 - 5.6
Fixed in 5.6.1
Are you affected? Scan for Free

TL;DR

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

httpclient5 is vulnerable to Missing Critical Step in Authentication in versions 5.6 - 5.6.

How to fix this

Upgrade the org.apache.httpcomponents.client5:httpclient5 library to a patch version.