Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Joe Gallo

#33519of 53,633
7.8Total CVSS
Vulnerabilities · 1
PT-2025-17726
7.8
2025-03-06
Apache · Apache Httpclient · CVE-2025-27820
**Name of the Vulnerable Software and Affected Versions** Apache HttpClient versions 5.4.0 through 5.4.2 **Description** A bug in PSL validation logic disables domain checks, affecting cookie management and host name verification. This issue was discovered by the Apache HttpClient team. **Recommendations** For Apache HttpClient versions 5.4.0 through 5.4.2, update to version 5.4.3 to resolve the issue. As a temporary workaround, consider restricting cookie management and host name verification until the update is applied.