CVE-2025-27820 is a high-severity vulnerability (CVSS 7.5) in Apache HttpClient 5.4.x, specifically affecting versions prior to 5.4.3, as well as NetApp products utilizing these HttpClient versions. The flaw lies in the PSL validation logic, which incorrectly disables domain checks, potentially compromising cookie management and hostname verification. While the vulnerability has a high impact on integrity (I:H) and requires no user interaction or privileges, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.4, < 5.4.3CPE matchmatch criteria | cpe:2.3:a:apache:httpclient:*:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.