logo

The 9.6 Crack in Java’s Foundation: Critical Undertow Flaw CVE-2025-12543

ID: 487ede43-dff8-5408-8ff2-0dedd8b339e2

STIX ID: report--487ede43-dff8-5408-8ff2-0dedd8b339e2

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-01-09

Date Updated: 2026-04-23

Author: Ddos

...
...

CVE-2025-12543 is a critical Host header validation flaw in the Undertow web server (used by WildFly and JBoss EAP) with a CVSS of 9.6; it permits remote, unauthenticated attackers to perform cache poisoning, internal network probing (SSRF-like behavior), and session hijacking. Administrators are urged to apply vendor patches and implement strict Host header validation to mitigate widespread enterprise impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.