CVE-2025-27820
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
Affected (2)
Products: Apache: Httpclient · Netapp: Ontap Tools
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.4 to 5.4.3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10 |
References (5)
Source: security@apache.org
Issue TrackingPatch
Source: security@apache.org
Issue TrackingPatch
Source: security@apache.org
Mailing ListPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.