CVE-2025-27820: Apache HttpComponents: PSL (Public Suffix List) validation bypass
Published Apr 24, 2025
·Updated
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
Affected Software
4 affected componentsFixes available
Apache HttpClient>=5.4
maven/org.apache.httpcomponents.client5:httpclient5>=5.4-alpha1<5.4.3
5.4.3
Apache HttpClient>=5.4<5.4.3
NetApp Ontap Tools Vmware Vsphere=10
Remediation
Patch Available
Patch Available
Event History
Apr 24, 2025
CVE Published
via MITRE·11:44 AM
Data Sourced
via MITRE·11:44 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
RemedyAffected Software
Advisory Published
via GitHub·12:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-27820?
CVE-2025-27820 is considered a medium severity vulnerability due to its impact on cookie management and hostname verification.
2
How do I fix CVE-2025-27820?
To fix CVE-2025-27820, upgrade Apache HttpClient to version 5.4.3 or later.
3
What versions of Apache HttpClient are affected by CVE-2025-27820?
CVE-2025-27820 affects Apache HttpClient versions 5.4.x prior to 5.4.3.
4
What are the risks associated with CVE-2025-27820?
The risks associated with CVE-2025-27820 include potential security breaches due to disabled domain checks in cookie management.
5
Who discovered CVE-2025-27820?
CVE-2025-27820 was discovered by the Apache HttpClient team.