We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
Reserved 2025-03-07 | Published 2025-04-24 | Updated 2025-05-16 | Assigner apachePSL Validation Bypass in Apache HttpClient 5.4.x
Joe Gallo
github.com/apache/httpcomponents-client/pull/574
github.com/apache/httpcomponents-client/pull/621
hc.apache.org/httpcomponents-client-5.4.x/index.html
lists.apache.org/thread/55xhs40ncqv97qvoocok44995xp5kqn8
Support options