A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NApache Httpclient
APPApache5.4 – 5.4.3 (excl.)Netapp Ontap Tools
APPNetapp10
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
Related vulnerabilities
CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
CVE-2026-71290CRITICAL9.1same product
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerific...
CVE-2024-52533CRITICAL9.8PL ✓same product
Buffer overflow w GNOME GLib — błąd off-by-one w obsłudze SOCKS4
CVE-2024-28752CRITICAL9.3PL ✓same product
SSRF w Apache CXF przez Aegis DataBinding — ataki na usługi webowe
CVE-2013-4366CRITICAL9.8PL ✓same product
Apache HttpClient 4.3.x — brak weryfikacji X509HostnameVerifier (null pointer)