Vulnerabilities > Apache > Httpclient

DATE CVE VULNERABILITY TITLE RISK
2020-12-02 CVE-2020-13956 Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
network
low complexity
apache quarkus oracle netapp
5.3
2017-10-30 CVE-2013-4366 Improper Input Validation vulnerability in Apache Httpclient 4.3
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
network
low complexity
apache CWE-20
critical
9.8