CVE-2025-12543
criticalCVSS v3 Base Score
9.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
EPSS Score
0.0%
Exploitation probability in 30 days
Top 88% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Confidentiality
High
Integrity
High
Availability
Low
Published: January 7, 2026 (127 days ago)
Last Modified: April 29, 2026
Vendor: Apache
Source: MITRE
Vulnerability Report
Generated by CyberWatcher
Description
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.
CWE
CWE-20Affected Products
Red Hat Red Hat build of Apache Camel 4.14.4 for Spring Boot 3.5.11Red Hat Red Hat JBoss Enterprise Application Platform 7.4Red Hat Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7Red Hat Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8Red Hat Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9Red Hat Red Hat JBoss Enterprise Application Platform 8.0Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Red Hat Red Hat JBoss Enterprise Application Platform 8.1Red Hat Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8