All 2 CVE vulnerabilities found in Apache HttpComponents Client, with AI-generated Chinese analysis, references, and POCs.
Vendor: Apache Software Foundation
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-71290 | Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM) CWE-295 | - | - | 2026-08-11 |
| CVE-2026-64607 | Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS CWE-772 | - | - | 2026-07-31 |
All 2 known CVE vulnerabilities affecting Apache HttpComponents Client with full Chinese analysis, references, and POCs where available.