← Back

CVE-2025-27820

nvd nist
Published: Apr 24, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release

Affected (2)

1 product
Httpclient
1 product
Ontap Tools
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 5.4 to 5.4.3
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10

References (5)

Source: security@apache.org
Issue TrackingPatch
Source: security@apache.org
Issue TrackingPatch
Source: security@apache.org
Mailing ListPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.