CVE-2020-13956: Apache Httpclient

Medium severity, CVSS 5.3. EPSS: 9% chance of exploitation in the next 30 days.

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

Affected products

  • Apache Httpclient: before 4.5.13 (fixed in 4.5.13); from 5.0.0, before 5.0.3 (fixed in 5.0.3)
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Oracle Commerce Guided Search: version 11.3.2 only
  • Oracle Communications Cloud Native Core Service Communication Proxy: version 1.14.0 only
  • Oracle Data Integrator: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Jd Edwards Enterpriseone Orchestrator: before 9.2.6.0 (fixed in 9.2.6.0)
  • Oracle Jd Edwards Enterpriseone Tools: before 9.2.6.0 (fixed in 9.2.6.0)
  • Oracle Nosql Database: before 20.3 (fixed in 20.3)
  • Oracle PeopleSoft Enterprise PeopleTools: version 8.57 only; version 8.58 only
  • Oracle PeopleSoft Enterprise Pt PeopleTools: version 8.57 only; version 8.58 only; version 8.59 only
  • Oracle Primavera Unifier: from 17.7, up to and including 17.12; version 16.1 only; version 16.2 only; version 18.8 only; version 19.12 only; version 20.12 only
  • Oracle Retail Customer Management And Segmentation Foundation: from 16.0, up to and including 19.0
  • Oracle Spatial Studio: before 20.1.1 (fixed in 20.1.1)
  • Oracle SQL Developer: before 20.4.1.407.0006 (fixed in 20.4.1.407.0006); before 21.99 (fixed in 21.99)
  • Oracle WebLogic Server: version 12.2.1.4.0 only; version 14.1.1.0.0 only
  • Quarkus Quarkus: before 1.7.6 (fixed in 1.7.6)

Published 2020-12-02. Last modified 2026-10-08.