A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
Metrics
Affected Vendors & Products
References
History
Tue, 29 Apr 2025 03:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Thu, 24 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-295 | |
Metrics |
cvssV3_1
|
Thu, 24 Apr 2025 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release | |
Title | Apache HttpComponents: PSL (Public Suffix List) validation bypass | |
References |
|

Status: PUBLISHED
Assigner: apache
Published: 2025-04-24T11:44:25.986Z
Updated: 2025-04-24T15:00:16.197Z
Reserved: 2025-03-07T12:47:46.839Z
Link: CVE-2025-27820

Updated: 2025-04-24T15:00:10.537Z

Status : Awaiting Analysis
Published: 2025-04-24T12:15:16.723
Modified: 2025-04-29T13:52:47.470
Link: CVE-2025-27820
