← back
CVE-2025-27820

Apache HttpComponents: PSL (Public Suffix List) validation bypass

CVSS 7.5 HIGHEPSS 0.7%CWE-295
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
24 Apr 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →