Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
A security vulnerability has been identified in the Undertow Java web server affecting multiple Ubuntu releases, including 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS, and 16.04 LTS. The flaw arises from improper validation of the Host header in incoming HTTP requests, potentially allowing remote att...
A vulnerability in HPE Telco Service Activator, reported on February 19, 2026, allows attackers to bypass access restrictions. The flaw is linked to improper input validation in the Undertow HTTP server core used by the product, specifically failing to validate the Host header.
A critical vulnerability, tracked as CVE-2025-12543, has been identified in the Undertow HTTP server, affecting Java applications like WildFly and JBoss EAP. This flaw allows attackers to hijack user sessions, leading to potential unauthorized access and compromise of internal systems.