Host Header Vulnerability in Undertow HTTP Server for WildFly and JBoss EAP
CVE-2025-12543
Key Information:
What is CVE-2025-12543?
A flaw exists in the core of the Undertow HTTP server, utilized by WildFly and JBoss EAP. This vulnerability arises from inadequate validation of the Host header in incoming HTTP requests. Malicious or malformed Host headers are not properly rejected, allowing attackers to exploit this weakness. Consequently, they can poison caches, perform scans of internal networks, or hijack user sessions, posing serious security risks to affected applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 0:4.0.10-1.redhat_00001.1.el8eap
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 0:1.82.0-1.redhat_00001.1.el8eap
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 0:801.3.0-1.GA_redhat_00001.1.el8eap
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved