CVE-2025-12543Critical· 9.6▾ AbyssalPoC availableA flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containi…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 52.8 · likelihood 0.3 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.2%
1.2% → 1.4%
1 GitHub repo
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.
build_of_apache_camel < 4.14.4data_grid = 8.0fuse = 7.0.0jboss_enterprise_application_platform >= 8.0, < 8.0.12jboss_enterprise_application_platform >= 8.1.0, < 8.1.3jboss_enterprise_application_platformjboss_enterprise_application_platform = 7.0.0jboss_enterprise_application_platform_expansion_packprocess_automation = 7.0single_sign-on = 7.0undertow < 2.2.39undertow >= 2.3.0, < 2.3.21Upgrade past the affected range:
build_of_apache_camel 4.14.4jboss_enterprise_application_platform 8.1.3undertow 2.3.21Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-9784High· 7.5A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters
CVE-2024-3884High· 7.5A flaw was found in Undertow that can cause remote denial of service attacks
CVE-2021-45105Medium· 5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups
CVE-2026-18217Low· 3.4A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution
CVE-2026-18211Medium· 4.2A flaw was found in the secure-client-uris client policy executor within Keycloak core services
CVE-2026-18206Low· 3.7A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services