VYPR

cxf-rt-transports-http-netty-client

by Apache

CVEs (1)

  • CVE-2026-107938Oct 9, 2026
    risk 0.00cvss —epss —

    In Apache CXF, the Netty-based HTTP client transport (cxf-rt-transports-http-netty-client) did not verify that the hostname in the server’s TLS certificate matched the host being called. This applied over both HTTP/1.1 and HTTP/2, even when disableCNCheck was left at its…