CVE-2025-27820

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*

History

16 Jul 2025, 14:48

Type Values Removed Values Added
CPE cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*
First Time Netapp ontap Tools
Apache httpclient
Netapp
Apache
References () https://github.com/apache/httpcomponents-client/pull/574 - () https://github.com/apache/httpcomponents-client/pull/574 - Issue Tracking, Patch
References () https://hc.apache.org/httpcomponents-client-5.4.x/index.html - () https://hc.apache.org/httpcomponents-client-5.4.x/index.html - Product
References () https://security.netapp.com/advisory/ntap-20250516-0003/ - () https://security.netapp.com/advisory/ntap-20250516-0003/ - Third Party Advisory
References () https://lists.apache.org/thread/55xhs40ncqv97qvoocok44995xp5kqn8 - () https://lists.apache.org/thread/55xhs40ncqv97qvoocok44995xp5kqn8 - Mailing List, Patch
References () https://github.com/apache/httpcomponents-client/pull/621 - () https://github.com/apache/httpcomponents-client/pull/621 - Issue Tracking, Patch

16 May 2025, 23:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250516-0003/ -

24 Apr 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-24 12:15

Updated : 2025-07-16 14:48


NVD link : CVE-2025-27820

Mitre link : CVE-2025-27820


JSON object : View

Products Affected

apache

  • httpclient

netapp

  • ontap_tools
CWE

No CWE.