
Critical Apache HttpComponents Flaw Allows Server Impersonation in MITM Attacks
A critical vulnerability in Apache HttpComponents Client could allow attackers to impersonate trusted servers during man-in-the-middle (MITM) attacks when applications use the asynchronous HttpClient implementation. Tracked as CVE-2026-71290, the issue stems from improper TLS hostname verification in Apache HttpComponents Client versions 5.4 through 5.6.3. The vulnerability affects applications configured with HostnameVerificationPolicy#BUILTIN while using the async […]
The post Critical Apache HttpComponents Flaw Allows Server Impersonation in MITM Attacks appeared first on Cyber Security News.