CVE-2013-4366: Apache Httpclient

Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.

http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.

Affected products

  • Apache Httpclient: version 4.3 only

Published 2017-10-30. Last modified 2026-06-16.