Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40542.json
https://bugzilla.redhat.com/show_bug.cgi?id=2460518
https://access.redhat.com/security/cve/CVE-2026-40542
https://access.redhat.com/errata/RHSA-2026:60259
https://access.redhat.com/errata/RHSA-2026:60256
https://access.redhat.com/errata/RHSA-2026:60254
https://access.redhat.com/errata/RHSA-2026:60252
https://access.redhat.com/errata/RHSA-2026:60251
https://access.redhat.com/errata/RHSA-2026:60250
https://access.redhat.com/errata/RHSA-2026:60249
https://access.redhat.com/errata/RHSA-2026:60248
https://access.redhat.com/errata/RHSA-2026:60247