Appsecure logo

CVE-2025-12543: Critical Vulnerability in RedHat Undertow

CVE-2025-12543 is a critical vulnerability in RedHat's Undertow HTTP server, affecting various products. This flaw allows attackers to exploit improperly validated Host headers, resulting in severe security risks. Immediate action is required from organizations to mitigate potential threats.

CRITICALCVSS 9.6 · Published January 7, 2026

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

CVE-2025-12543 is a critical vulnerability identified in the Undertow HTTP server core, widely used in RedHat's Java applications such as WildFly and JBoss EAP. With a CVSS score of 9.6, this vulnerability allows attackers to exploit the improper validation of the Host header in incoming HTTP requests. As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions. Organizations utilizing affected products are at significant risk.

Given the critical severity of this vulnerability, organizations should prioritize patching immediately. Failure to address this issue could lead to unauthorized access and significant data breaches, posing a serious risk to organizational integrity and operational continuity.

Currently, there are no known exploits or public proof of concepts available, but the potential for exploitation remains high. Organizations are advised to stay vigilant for updates from RedHat regarding remediation actions and implement necessary security measures.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.