CLEANSTART-2026-OB74177
Dashboard / Vulnerabilities / CLEANSTART-2026-OB74177
CLEANSTART-2026-OB74177
Summary: Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5
Details: Multiple security vulnerabilities affect the spring-boot package. Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5. See references for individual vulnerability details.
References: https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-OB74177.json, https://osv.dev/vulnerability/CVE-2026-22745, https://osv.dev/vulnerability/CVE-2026-41848, https://osv.dev/vulnerability/CVE-2026-41851, https://osv.dev/vulnerability/CVE-2026-47842, https://osv.dev/vulnerability/CVE-2026-54399, https://osv.dev/vulnerability/CVE-2026-54428, https://osv.dev/vulnerability/CVE-2026-64607, https://osv.dev/vulnerability/CVE-2026-71290, https://osv.dev/vulnerability/ghsa-4265-ccf5-phj5, https://osv.dev/vulnerability/ghsa-4g9r-vxhx-9pgx, https://nvd.nist.gov/vuln/detail/CVE-2026-22745, https://nvd.nist.gov/vuln/detail/CVE-2026-41848, https://nvd.nist.gov/vuln/detail/CVE-2026-41851, https://nvd.nist.gov/vuln/detail/CVE-2026-47842, https://nvd.nist.gov/vuln/detail/CVE-2026-54399, https://nvd.nist.gov/vuln/detail/CVE-2026-54428, https://nvd.nist.gov/vuln/detail/CVE-2026-64607, https://nvd.nist.gov/vuln/detail/CVE-2026-71290
Affected packages
Package
Name: spring-boot
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
