We found results for “”
CVE-2025-12543
Good to know:
Date: January 7, 2026
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.
Severity Score
Related Resources (11)
Severity Score
Weakness Type (CWE)
Improper Input Validation
CWE-20Top Fix
Upgrade Version
Upgrade to version io.undertow:undertow-core:2.3.21.Final;io.undertow:undertow-core:2.2.39.Final
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | LOW |
Vulnerabilities
Projects
Contact Us


