← Vulnerability feed

Vulnerability record · CVE-2025-27820 · published 24 April 2025

CVE-2025-27820: Apache httpclient improper certificate validation vulnerability

Apache · Httpclient

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release

7.5 CVSS 3.1 High EPSS 0.95% · top 40.3% CWE-295 · Improper certificate validation
7.5CVSS 3.1 base score
0.95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-27820 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed7.8CVE-2021-3156Sudo off-by-one heap overflow allows root privilege escalationSudo before 1.9.5p2 contains an off-by-one error leading to a heap-based buffer overflow. Triggering it via 'sudoedit -s' with a command-line argumen…KEVEPSS 100%analysed9.8CVE-2024-52533Gnome glib classic buffer overflow vulnerabilitygio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient f…EPSS 1.3%9.8CVE-2024-1351Mongodb improper certificate validation vulnerabilityUnder certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connect…EPSS 0.50%9.8CVE-2013-4366Apache httpclient improper input validation vulnerabilityhttp/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows a…EPSS 3.3%9.3CVE-2024-28752Apache cxf server-side request forgery (ssrf) vulnerabilityA SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style att…EPSS 2.5%9.1CVE-2026-71290Apache httpclient improper certificate validation vulnerabilityImproper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe…EPSS 0.33%8.7CVE-2024-7254Google protobuf uncontrolled resource consumption vulnerabilityAny project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exce…EPSS 2.8%

Source: NIST National Vulnerability Database (record CVE-2025-27820), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.