Apache HttpComponents Client
89%
Total Score
97
81
78
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-64607 org.apache.httpcomponents.client5:httpclient5 is vulnerable to Missing Release of Resource after Effective Lifetime in versions 5.0-alpha1 - 5.6.3. | 5.0-alpha1 - 5.6.3 | Medium |
AIKIDO-2026-10647 httpclient5 is vulnerable to Missing Critical Step in Authentication in versions 5.6 - 5.6. | 5.6 - 5.6 | High |
CVE-2025-27820 org.apache.httpcomponents.client5:httpclient5 is vulnerable to Improper Certificate Validation in versions 5.4-alpha1 - 5.4.3. | 5.4-alpha1 - 5.4.3 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.apache.httpcomponents.core5:httpcore5 Version * | — | — |
org.apache.httpcomponents.core5:httpcore5-h2 Version * | — | — |
org.slf4j:slf4j-api Version * | — | — |
org.conscrypt:conscrypt-openjdk-uber Version * | — | — |
org.apache.commons:commons-compress Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant