Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.undertow/undertow-core
  4. ›
  5. CVE-2025-12543

CVE-2025-12543: Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests

January 7, 2026 (updated January 21, 2026)

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests. As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.

References

  • access.redhat.com/errata/RHSA-2026:0383
  • access.redhat.com/errata/RHSA-2026:0384
  • access.redhat.com/errata/RHSA-2026:0386
  • access.redhat.com/security/cve/CVE-2025-12543
  • bugzilla.redhat.com/show_bug.cgi?id=2408784
  • github.com/advisories/GHSA-j382-5jj3-vw4j
  • github.com/undertow-io/undertow
  • github.com/undertow-io/undertow/pull/1857
  • github.com/undertow-io/undertow/pull/1860
  • github.com/undertow-io/undertow/releases/tag/2.3.21.Final
  • nvd.nist.gov/vuln/detail/CVE-2025-12543

Code Behaviors & Features

Detect and mitigate CVE-2025-12543 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

Version 2.4.0.Alpha1, all versions before 2.3.21.Final

Fixed versions

  • 2.3.21.Final

Solution

Upgrade to version 2.3.21.Final or above.

Impact 9.6 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

Learn more about CVSS

Weakness

  • CWE-20: Improper Input Validation

Source file

maven/io.undertow/undertow-core/CVE-2025-12543.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 04 Feb 2026 00:35:17 +0000.