We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-27820

Apache HttpComponents: PSL (Public Suffix List) validation bypass



Description

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release

Reserved 2025-03-07 | Published 2025-04-24 | Updated 2025-05-16 | Assigner apache

Problem types

PSL Validation Bypass in Apache HttpClient 5.4.x

Product status

Default status
unaffected

5.4.0 before 5.4.3
affected

Credits

Joe Gallo remediation developer

References

github.com/apache/httpcomponents-client/pull/574

github.com/apache/httpcomponents-client/pull/621

hc.apache.org/httpcomponents-client-5.4.x/index.html

lists.apache.org/thread/55xhs40ncqv97qvoocok44995xp5kqn8 vendor-advisory

cve.org (CVE-2025-27820)

nvd.nist.gov (CVE-2025-27820)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-27820

Support options

Helpdesk Chat, Email, Knowledgebase