CVE-2025-12543
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
- EPSS probability
- 1.35%
- CWE
- CWE-20
- Published
- 2026-01-07
- Last modified
- 2026-09-07
Affected products
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
Weakness type
Related vulnerabilities
- CVE-2026-78900 — Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exec
- CVE-2026-79111 — Improper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execu
- CVE-2026-79230 — Improper input validation in ANGLE in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to potent
- CVE-2026-79182 — Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exec
- CVE-2026-78963 — Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exec
- CVE-2026-79008 — Improper input validation in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had
- CVE-2026-87553 — Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had com
- CVE-2026-87510 — Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromis