Improper Neutralization of HTTP Headers for Scripting Syntax in Undertow - CVE-2025-12543

 

Improper Neutralization of HTTP Headers for Scripting Syntax in Undertow - CVE-2025-12543

Published: January 10, 2026


Vulnerability identifier: #VU121145
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N]
CVE-ID: CVE-2025-12543
CWE-ID: CWE-644
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to improper input validation when processing HTTP requests. A remote non-authenticated attacker can send a specially crafted HTTP request with an arbitrary Host header that will be accepted by the application.

Successful exploitation of the vulnerability may allow an attacker to perform cross-site scripting, cache poisoning or session hijacking attacks.


Affected software

Undertow
watsonx.data
JBoss Enterprise Application Platform
Rational Performance Tester
DevOps Test Performance
Terracotta
IBM InfoSphere Information Server
Ubuntu
Oracle Communications Cloud Native Core Unified Data Repository
Oracle Communications Cloud Native Core Policy
eap8-jboss-el (Red Hat package)
eap8-eventstream (Red Hat package)
undertow (Ubuntu package)
eap8-bouncycastle (Red Hat package)
eap8-undertow (Red Hat package)
eap8-jboss-threads (Red Hat package)
eap8-wildfly-elytron (Red Hat package)
eap8-apache-cxf (Red Hat package)
eap8-wildfly-clustering (Red Hat package)
eap8-hibernate (Red Hat package)
eap8-wildfly-javadocs (Red Hat package)
eap8-wildfly (Red Hat package)
eap8-eap-product-conf-parent (Red Hat package)
Red Hat Camel for Spring Boot

How to mitigate CVE-2025-12543

Install updates from vendor's website.

watsonx.data - update to 2.3.1
JBoss Enterprise Application Platform - update to 8.1.3
DevOps Test Performance - update to 11.0.8
Terracotta - update to 11.1.0.11
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 2
eap8-jboss-el (Red Hat package) - addressed in versions api_5.0_spec-4.0.2-1.Final_redhat_00001.1.el8eap, api_5.0_spec-4.0.2-1.Final_redhat_00001.1.el9eap
eap8-eventstream (Red Hat package) - addressed in versions 1.0.1-3.redhat_00003.1.el8eap, 1.0.1-3.redhat_00003.1.el9eap
undertow (Ubuntu package) - addressed in versions 1.3.16-1ubuntu0.1~esm1, 1.4.23-3ubuntu0.1~esm1, 2.0.29-1ubuntu0.1~esm1, 2.2.16-1ubuntu0.1~esm1, 2.3.8-2ubuntu0.1~esm1
eap8-bouncycastle (Red Hat package) - addressed in versions 1.82.0-1.redhat_00001.1.el8eap, 1.82.0-1.redhat_00001.1.el9eap
eap8-undertow (Red Hat package) - addressed in versions 2.3.20-2.SP4_redhat_00001.1.el8eap, 2.3.20-2.SP4_redhat_00001.1.el9eap
eap8-jboss-threads (Red Hat package) - addressed in versions 2.5.0-1.redhat_00001.1.el8eap, 2.5.0-1.redhat_00001.1.el9eap
eap8-wildfly-elytron (Red Hat package) - addressed in versions 2.6.6-1.Final_redhat_00001.1.el8eap, 2.6.6-1.Final_redhat_00001.1.el9eap
eap8-apache-cxf (Red Hat package) - addressed in versions 4.0.10-1.redhat_00001.1.el8eap, 4.0.10-1.redhat_00001.1.el9eap
Red Hat Camel for Spring Boot - update to 4.14.4
eap8-wildfly-clustering (Red Hat package) - addressed in versions 5.0.12-1.Final_redhat_00001.1.el8eap, 5.0.12-1.Final_redhat_00001.1.el9eap
eap8-hibernate (Red Hat package) - addressed in versions 6.6.36-1.Final_redhat_00001.1.el8eap, 6.6.36-1.Final_redhat_00001.1.el9eap
eap8-wildfly-javadocs (Red Hat package) - addressed in versions 8.1.1-4.GA_redhat_00007.1.el8eap, 8.1.1-4.GA_redhat_00007.1.el9eap
eap8-wildfly (Red Hat package) - addressed in versions 8.1.3-4.GA_redhat_00006.1.el8eap, 8.1.3-4.GA_redhat_00006.1.el9eap
eap8-eap-product-conf-parent (Red Hat package) - addressed in versions 801.3.0-1.GA_redhat_00001.1.el8eap, 801.3.0-1.GA_redhat_00001.1.el9eap

External References

Related Security Bulletins