HIGHMaven

Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests

Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests

CVE-2025-12543Published 8 months agoUpdated 5 days agoSource: OSV

Affected packages

  • io.undertow:undertow-core2.3.0.Alpha1 → 2.3.21.Final

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests | HackTribune