Vulnerabilities
Vulnerable Software
Apache:  >> Httpclient  >> 5.4  Security Vulnerabilities
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2.
CVSS Score
5.3
EPSS Score
0.003
Published
2026-07-31
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
CVSS Score
7.5
EPSS Score
0.009
Published
2025-04-24


Contact Us

Shodan ® - All rights reserved