CVE-2025-27820
published 2025-04-24CVE-2025-27820: A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.79%
52.3th percentile
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | httpclient | >= 5.4 < 5.4.3 | 5.4.3 |
| apache_software_foundation | apache_httpcomponents | >= 5.4.0 < 5.4.3 | 5.4.3 |
| debian | httpcomponents-client | — | — |
| netapp | ontap_tools | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_debian7.5LOW
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache HttpClient disables domain checks
ghsa·2025-04-24
CVE-2025-27820 [HIGH] CWE-295 Apache HttpClient disables domain checks
Apache HttpClient disables domain checks
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release.
OSV
Apache HttpClient disables domain checks
osv·2025-04-24
CVE-2025-27820 [HIGH] Apache HttpClient disables domain checks
Apache HttpClient disables domain checks
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release.
OSV
CVE-2025-27820: A bug in PSL validation logic in Apache HttpClient 5
osv·2025-04-24·CVSS 7.5
CVE-2025-27820 [HIGH] CVE-2025-27820: A bug in PSL validation logic in Apache HttpClient 5
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
Oracle
Oracle Oracle GoldenGate Risk Matrix: Java Delivery (Apache HttpClient) — CVE-2025-27820
vendor_oracle·2025-07-15·CVSS 7.5
CVE-2025-27820 [HIGH] Oracle Oracle GoldenGate Risk Matrix: Java Delivery (Apache HttpClient) — CVE-2025-27820
Oracle Oracle GoldenGate Risk Matrix: Java Delivery (Apache HttpClient) vulnerability
CVE: CVE-2025-27820
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Red Hat
org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents: PSL (Public Suffix List) validation bypass
vendor_redhat·2025-04-24·CVSS 7.5
CVE-2025-27820 [HIGH] CWE-295 org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents: PSL (Public Suffix List) validation bypass
org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents: PSL (Public Suffix List) validation bypass
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
A flaw was found in Apache HttpClient. This vulnerability allows unauthorized access or information disclosure via disabled Public Suffix List (PSL) validation, affecting cookie management and hostname verification.
Statement: This vulnerability is rated Moderate due to the high attack complexity required for exploitation, the limited impact on confidentiality, and the fact that the issue does not allow direct system compromise or denial of service. While the failure to loa
Debian
CVE-2025-27820: httpcomponents-client - A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks,...
vendor_debian·2025·CVSS 7.5
CVE-2025-27820 [HIGH] CVE-2025-27820: httpcomponents-client - A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks,...
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
2025-04-24
Published