ZeroHour

CVE-2025-27820

CVSS 3.1
7.5 high
EPSS
<1%p57
Published
()
Modified
Description

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release

Vendors
apachenetapp
Products
httpclient, ontap tools
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.