Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2405-1 | httpcomponents-client security update |
Debian DSA |
DSA-4772-1 | httpcomponents-client security update |
EUVD |
EUVD-2021-1284 | Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. |
Github GHSA |
GHSA-7r82-7xv7-xcpj | Cross-site scripting in Apache HttpClient |
Ubuntu USN |
USN-5239-1 | HttpClient vulnerability |
Fri, 09 Oct 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Subscriptions
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-08T18:44:13.434Z
Reserved: 2020-06-08T00:00:00.000Z
Link: CVE-2020-13956
Updated: 2025-12-01T15:45:49.435Z
Status : Modified
Published: 2020-12-02T17:15:14.547
Modified: 2026-10-08T19:16:54.573
Link: CVE-2020-13956
OpenCVE Enrichment
No data.
-
CWE-20
Improper Input Validation
- NVD-CWE-noinfo
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN