CVE-2025-27820

Severity
7.5HIGH
EPSS
0.3%
top 44.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 24
Latest updateJul 15

Description

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDapache/httpclient5.45.4.3

Also affects: Ontap Tools 10

Patches

🔴Vulnerability Details

4
GHSA
Apache HttpClient disables domain checks2025-04-24
CVEList
Apache HttpComponents: PSL (Public Suffix List) validation bypass2025-04-24
OSV
Apache HttpClient disables domain checks2025-04-24
OSV
CVE-2025-27820: A bug in PSL validation logic in Apache HttpClient 52025-04-24

📋Vendor Advisories

3
Oracle
Oracle Oracle GoldenGate Risk Matrix: Java Delivery (Apache HttpClient) — CVE-2025-278202025-07-15
Red Hat
org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents: PSL (Public Suffix List) validation bypass2025-04-24
Debian
CVE-2025-27820: httpcomponents-client - A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks,...2025
CVE-2025-27820 (HIGH CVSS 7.5) | A bug in PSL validation logic in Ap | cvebase.io