CRITICAL🇵🇱 Wersja polska

CVE-2025-12543

CVSS 9.6v3.1pub. 2026-01-07upd. 2026-09-04

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.

🤖 AI Analysis
How it works

The Undertow server, used among others in WildFly, JBoss EAP and other Java applications, does not reject HTTP requests containing distorted or malicious Host header values. An attacker can craft a request with a manipulated Host header, which will be processed by the server without verification. This leads to the possibility of executing Host Header Injection attacks, including cache poisoning, scanning of internal network resources (SSRF), and interception of user sessions.

Impact

An attacker may poison the server or network intermediary cache, conduct scanning of internal network resources, or hijack sessions of logged-in users, which may lead to violation of data confidentiality and integrity.

Mitigation & patch

Patches available from the vendor should be applied according to the errata: RHSA-2026:0383, RHSA-2026:0384, RHSA-2026:0386, RHSA-2026:3889, RHSA-2026:3890 published by Red Hat

Who is affected

Red Hat Build of Apache Camel, Red Hat Data Grid, Red Hat Fuse, Red Hat JBoss Enterprise Application Platform — versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
  • Red Hat Build Of Apache Camel

    APP
    Redhat
    < 4.14.4
  • Red Hat Data Grid

    APP
    Redhat
    8.0
  • Red Hat Fuse

    APP
    Redhat
    7.0.0
  • Red Hat Jboss Enterprise Application Platform

    APP
    Redhat
    7.0.08.1.0 – 8.1.3 (excl.)8.0 – 8.0.12 (excl.)
  • Red Hat Jboss Enterprise Application Platform Expansion Pack

    APP
    Redhat
    all versions
  • Red Hat Process Automation

    APP
    Redhat
    7.0
  • Red Hat Single Sign On

    APP
    Redhat
    7.0
  • Red Hat Undertow

    APP
    Redhat
    < 2.2.392.3.0 – 2.3.21 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2017-12149CRITICAL9.8⚠ KEVPL ✓same product

RCE przez niebezpieczną deserializację w JBoss HTTP Invoker (EAP 5.2)

CVE-2016-4437CRITICAL9.8⚠ KEVPL ✓same product

Apache Shiro RCE przez nieskonfigurowany klucz szyfrowania 'remember me'

CVE-2015-1427CRITICAL9.8⚠ KEVPL ✓same product

Elasticsearch: ucieczka z sandboksa Groovy i zdalne wykonanie poleceń

CVE-2022-4361CRITICAL10.0PL ✓same product

XSS w Keycloak — podatność w obsłudze SAML/OIDC umożliwia wykonanie złośliwych skryptów

CVE-2021-31917CRITICAL9.8PL ✓same product

Pominięcie uwierzytelnienia REST w Red Hat DataGrid i Infinispan