StackRadar

CVE-2025-27820

High

Advisory

Published 24 Apr 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
1 of 1
affected package

Apache HttpClient disables domain checks

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
httpclient5maven5.4, 5.4.1, 5.4.25.4.38
OSV records
GHSA-73m2-qfq3-56cx

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
nacosygqygq2Verified publisher2.1.101 of 4See more

nacos ygqygq2 2.1.10

1 of the 4 container images this version deploys carry CVE-2025-27820.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.20e951a1d07bb
httpclient5@5.4.2
5.4.3

Open the chart page →

4,983
opensearchcaptnbpVerified publisher3.1.11 of 2See more

opensearch captnbp 3.1.1

1 of the 2 container images this version deploys carry CVE-2025-27820.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.19.269588c664014
httpclient5@5.4.1
5.4.3

Open the chart page →

998
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2025-27820.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
httpclient5@5.4.2
5.4.3

Open the chart page →

12,019
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2025-27820.

Container imageDigestPackageFixed in
resurfaceio/resurface:3.7.84d5cda2f64109
httpclient5@5.4.2
5.4.3

Open the chart page →

7,432
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-27820.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
httpclient5@5.4.2
5.4.3

Open the chart page →

7,792
dss-validation-servicefiware0.0.191 of 1See more

dss-validation-service fiware 0.0.19

1 of the 1 container images this version deploys carry CVE-2025-27820.

Container imageDigestPackageFixed in
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
httpclient5@5.4.1
5.4.3

Open the chart page →

4,536
nacosnacos-yunyeVerified publisher1.0.31 of 1See more

nacos nacos-yunye 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-27820.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.130a39cb0c54d
httpclient5@5.4.2
5.4.3

Open the chart page →

1,783
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2025-27820.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
httpclient5@5.4
5.4.3

Open the chart page →

5,826
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-27820.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
httpclient5@5.4.2
5.4.3

Open the chart page →

7,792

Container images carrying it

8 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/fineract:1.12.1a83cf1980609
httpclient5@5.4.2
5.4.3
2
nacos/nacos-server:v3.0.20e951a1d07bb
httpclient5@5.4.2
5.4.3
1
nacos/nacos-server:v3.0.130a39cb0c54d
httpclient5@5.4.2
5.4.3
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
httpclient5@5.4
5.4.3
1
opensearchproject/opensearch:2.19.269588c664014
httpclient5@5.4.1
5.4.3
1
resurfaceio/resurface:3.7.84d5cda2f64109
httpclient5@5.4.2
5.4.3
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
httpclient5@5.4.2
5.4.3
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
httpclient5@5.4.1
5.4.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.