Improper Certificate Validation Affecting org.apache.httpcomponents.client5:httpclient5 package, versions [5.4.0,5.4.3)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.01% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHEHTTPCOMPONENTSCLIENT5-9804209
  • published24 Apr 2025
  • disclosed24 Apr 2025
  • creditApache HttpClient team

Introduced: 24 Apr 2025

NewCVE-2025-27820  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade org.apache.httpcomponents.client5:httpclient5 to version 5.4.3 or higher.

Overview

org.apache.httpcomponents.client5:httpclient5 is a HttpClient component of the Apache HttpComponents project.

Affected versions of this package are vulnerable to Improper Certificate Validation due to a bug in the validation logic of the Public Suffix List, which allows attackers to manipulate cookie management and host name verification, leading to unauthorized access or information disclosure.

CVSS Base Scores

version 4.0
version 3.1