The 9.6 Crack in Java’s Foundation: Critical Undertow Flaw CVE-2025-12543
ID: 487ede43-dff8-5408-8ff2-0dedd8b339e2
STIX ID: report--487ede43-dff8-5408-8ff2-0dedd8b339e2
Feed Name: securityonline.info
Threat Score
CVE-2025-12543 is a critical Host header validation flaw in the Undertow web server (used by WildFly and JBoss EAP) with a CVSS of 9.6; it permits remote, unauthenticated attackers to perform cache poisoning, internal network probing (SSRF-like behavior), and session hijacking. Administrators are urged to apply vendor patches and implement strict Host header validation to mitigate widespread enterprise impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
