CVE-2025-12543
A flaw was found in the Undertow HTTP server core, which is used inWildFly, JBoss EAP, and other Java applications. The Undertow library failsto properly validate the Host header in incoming HTTP requests.As a result,requests containing malformed or malicious Host headers are processedwithout rejection, enabling attackers to poison caches, perform internalnetwork scans, or hijack user sessions.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://www.cve.org/CVERecord?id=CVE-2025-12543
