Skip to content

CVE-2025-12543

CVE

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
January 9, 2026
Last Seen
April 2, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A security vulnerability has been identified in the Undertow Java web server affecting multiple Ubuntu releases, including 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS, and 16.04 LTS. The flaw arises from improper validation of the Host header in incoming HTTP requests, potentially allowing remote att...

A vulnerability in HPE Telco Service Activator, reported on February 19, 2026, allows attackers to bypass access restrictions. The flaw is linked to improper input validation in the Undertow HTTP server core used by the product, specifically failing to validate the Host header.

A critical vulnerability, tracked as CVE-2025-12543, has been identified in the Undertow HTTP server, affecting Java applications like WildFly and JBoss EAP. This flaw allows attackers to hijack user sessions, leading to potential unauthorized access and compromise of internal systems.

Public Exploits

Checking GitHub for proof-of-concept code…