AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-4366

CRITICAL · CVSS 9.8 EPSS 2.18%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-10-30 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2013-4366
Severity
CRITICAL
CVSS
9.8
EPSS
2.18%
Apache Java

Original NVD Description

http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.

Related CVEs

Other vulnerabilities affecting the same vendor(s)