CVE-2025-12543
A flaw in the Undertow HTTP server core allows attackers to send HTTP requests with malformed Host headers that are not properly validated. This can lead to cache poisoning, internal network scans, or session hijacking. The vulnerability is present in several Red Hat products that use Undertow.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
redhat build_of_apache_camel, redhat data_grid 8.0, redhat fuse 7.0.0, redhat jboss_enterprise_application_platform, redhat jboss_enterprise_application_platform -, redhat jboss_enterprise_application_platform 7.0.0, redhat jboss_enterprise_application_platform_expansion_pack -, redhat process_automation 7.0, redhat single_sign-on 7.0, redhat undertow
Real-world impact
An attacker could poison application caches, discover internal network services, or hijack user sessions by exploiting the unchecked Host header.
Why this severity
The CVSS score of 9.6 reflects a network‑based attack (AV:N) that requires low complexity (AC:L) and no privileges (PR:N). The vulnerability changes scope (S:C) and grants high confidentiality and integrity impact (C:H, I:H) while only affecting availability at a low level (A:L). User interaction is required (UI:R) because the attacker must send a crafted HTTP request.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jan 7, 2026 · Jan 7, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 28, 2026 · 8d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- access.redhat.com/errata/RHSA-2026:0383vendor advisory
- access.redhat.com/errata/RHSA-2026:0384vendor advisory
- access.redhat.com/errata/RHSA-2026:0386vendor advisory
- access.redhat.com/errata/RHSA-2026:33371
- access.redhat.com/errata/RHSA-2026:33372
- access.redhat.com/errata/RHSA-2026:3889vendor advisory
- access.redhat.com/errata/RHSA-2026:3890vendor advisory
- access.redhat.com/errata/RHSA-2026:3891vendor advisory
- access.redhat.com/errata/RHSA-2026:3892vendor advisory
- access.redhat.com/errata/RHSA-2026:4915
- access.redhat.com/errata/RHSA-2026:4916
- access.redhat.com/errata/RHSA-2026:4917
- access.redhat.com/errata/RHSA-2026:4924
- access.redhat.com/security/cve/CVE-2025-12543vendor advisory
- bugzilla.redhat.com/show_bug.cgiissue trackingvendor advisory
- security.access.redhat.com/data/csaf/v2/vex/2025/cve-2…