Undertow HTTP Server Used in Java Apps Vulnerability Allow Attackers to Hijack Sessions
A critical security flaw has been discovered in the Undertow HTTP server core, a widely used component in Java applications such as WildFly and JBoss EAP. The vulnerability, tracked as CVE-2025-12543, poses serious risks to application security by enabling attackers to hijack user sessions and compromise internal systems. The flaw exists in how Undertow handles HTTP […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
