Apache HttpComponents: PSL (Public Suffix List) validation bypass
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.9%
exploitation probability
0.9%top 40% of all CVEs
observed exploitation
nono source reports it
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
Apache Software Foundation · Apache HttpComponentsReferences
https://github.com/apache/httpcomponents-client/pull/574https://github.com/apache/httpcomponents-client/pull/621https://hc.apache.org/httpcomponents-client-5.4.x/index.htmlhttps://lists.apache.org/thread/55xhs40ncqv97qvoocok44995xp5kqn8https://security.netapp.com/advisory/ntap-20250516-0003/