Description

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.

INFO

Published Date :

2026-01-07T16:04:22.155Z

Last Modified :

2026-04-01T13:35:57.048Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-12543 vulnerability.

Vendors Products
Redhat
  • Apache Camel Hawtio
  • Apache Camel Spring Boot
  • Build Of Apache Camel
  • Data Grid
  • Enterprise Linux
  • Fuse
  • Jboss Data Grid
  • Jboss Enterprise Application Platform
  • Jboss Enterprise Application Platform Els
  • Jboss Enterprise Application Platform Expansion Pack
  • Jboss Enterprise Bpms Platform
  • Jboss Fuse
  • Jbosseapxp
  • Process Automation
  • Red Hat Single Sign On
  • Single Sign-on
  • Undertow

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact