CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-12543

Critical · CVSS 9.6

Undertow HTTP server — Host header validation bypass enabling cache poisoning, SSRF, and session hijacking

CVSS
9.6
nvd
EPSS
1.20%
65th pct
KEV
No
Class
oss containerizable
CWE-20, CWE-20

Description

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.

Search profile — drives PoC discovery

Symbols Host headerHttpServerExchangevalidateHostHeaderHostHeaderValidatorRequestParserStateHttpRequestParserParseStateio.undertow.serverio.undertow.util.HeadersUndertowOptionsREQUIRE_HOST_HTTP11
Keywords CVE-2025-12543Undertow Host header validationUndertow malformed Host headerWildFly Host header injectionJBoss EAP Host header bypassUndertow cache poisoningUndertow HTTP request smuggling HostUndertow CWE-20 improper input validationUndertow host header poison PoCUndertow SSRF host header
Versions: Undertow versions affected as referenced in RHSA-2026:0383, RHSA-2026:0384, RHSA-2026:0386, RHSA-2026:33371, RHSA-2026:33372

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

Maven io.undertow:undertow-core 0 → 2.2.39.Final
Maven io.undertow:undertow-core 2.3.0.Alpha1 → 2.3.21.Final

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-06-30T18:10:12.581Z