CVE-2025-12543Disclosure(redhat / build_of_apache_camel)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redhat build_of_apache_camel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_apache_camel
  • data_grid
  • fuse
  • jboss_enterprise_application_platform

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-25); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
build_of_apache_cameldata_gridfusejboss_enterprise_application_platformjboss_enterprise_application_platform_expansion_packprocess_automationsingle_sign-onundertow

4 versions affected across 8 products

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-02-13: 1Mentions · 2026-02-23: 1Mentions · 2026-02-24: 1Mentions · 2026-02-25: 2Mentions · 2026-03-02: 1Mentions · 2026-09-13: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-02-25: 1Technical Details · 2026-02-23: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-02: 1Technical Details · 2026-09-13: 102-1302-2302-2402-2503-0209-13
Signal classification3 categories
Disclosure
342.9%
General
228.6%
Patch
228.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-131
General1
2026-02-231
Patch1
2026-02-241
Disclosure1
2026-02-252
General1Patch1
2026-03-021
Disclosure1
2026-09-131
Disclosure1
Full discourse7 posts
  • AZGingerHacker@AZGingerHacker
    Disclosure

    👀 One for the AppSec & vulnerability research folks: CVE-2025-12543: Host Header Validation Bypass in Undertow A good reminder that something as simple as trusting attacker-controlled HTTP headers can create real security problems. Worth the read 👇 https://api.cyfluencer.com/s/cve-2025-12543-host-header-validation-bypass-in-undertow-29518 #CyberSecurity #AppSec #CVE #WebSecurity

    Post summary

    A brief tweet announcing CVE-2025-12543 (Host Header Validation Bypass in Undertow) with a link to further details, highlighting the risk of trusting attacker-controlled HTTP headers, but lacking exploit, PoC, or patch information.

    0102079
    378 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    HPE Telco Service Activator の脆弱性 CVE-2025-12543 が FIX:リモートアクセス制限回避の恐れ https://iototsecnews.jp/2026/02/23/hpe-telco-service-activator-vulnerability-allows-attackers-to-bypass-access-controls/ 通信事業者のネットワーク自動化を支える中核システム HPE Telco Service Activatorに、未認証のリモート攻撃者によるアクセス制限回避を許す、深刻な脆弱性 CVE-2025-12543 が発見されました。この脆弱性の本質は、システム内部で使用されている Undertow HTTPサーバが、リクエストに含まれる “Hostヘッダ” を適切に検証しないことにあります。 Hostヘッダは、ブラウザがアクセスしている Web サイトをサーバに伝える情報ですが、この値を攻撃者が操作することで、管理画面や機密データ領域へのすり抜けが可能になります。ご利用のチームは、ご注意ください。よろしければ、HPE での検索結果も、ご参照ください。 #CVE202512543 #HPE #TelcoServiceActivator #Vulnerability

    Post summary

    CVE‑2025‑12543 is a severe vulnerability in HPE Telco Service Activator caused by improper validation of the Host header in the Undertow HTTP server, enabling unauthenticated attackers to bypass access controls; the text provides technical details but no proof‑of‑concept, exploit, or report of active exploitation.

    02010296
    483 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Critical HPE Telco Service Activator Bug Lets Attackers Bypass Access Controls via Host-Header Abuse (CVE-2025-12543) HPE disclosed CVE-2025-12543 (CVSS 9.6) in Telco Service Activator where Undertow fails to properly validate the HTTP Host header, enabling remote access restriction bypass via crafted requests; affected versions are <10.5.0 and HPE urges immediate upgrade to 10.5.0. 🎯 Target: Global/Telecom #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/hpe-telco-activator-vulnerability-exposed/

    Post summary

    HPE disclosed CVE-2025-12543, a critical Host header validation flaw in Telco Service Activator with CVSS 9.6, and urges users to upgrade to version 10.5.0 to mitigate the remote access bypass.

    0102059
    196 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos HPE ❗ CVE-2025-12543 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-hpe-4/ https://t.co/wnrrXnVPHb

    Post summary

    The tweet announces CVE-2025-12543 affecting HPE products and directs readers to a link for more information, but offers no further technical or exploit details.

    00000116
    6.6K followersView on X
  • mysocAi@MysocAi
    Patch

    [CRITICAL] Critical Flaw in HPE Telco Service Activator Exposed CVE-2025-12543 allows remote access control bypass; HPE urges updates. CVE: CVE-2025-12543 … https://www.cyware.com/resources/threat-briefings/daily-threat-briefing/cyware-daily-threat-intelligence-february-23-2026

    Post summary

    HPE has disclosed a critical remote access control bypass flaw (CVE-2025-12543) and urges users to apply updates to mitigate the risk.

    000004
    3 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical HPE Telco Service Activator Flaw (CVE-2025-12543) Lets Attackers Bypass Host-Based Access Controls HPE warns a critical improper Host-header validation bug in the Undertow HTTP core used by Telco Service Activator can let remote attackers bypass access restrictions by abusing Host-based allowlists/routing controls in real deployments. Patch by upgrading to TSA 10.5.0+ and restrict exposure (VPN/admin-only) while monitoring for anomalous Host header values and unexpected routing behavior. 🎯 Target: Global/Telecommunications (HPE Telco Service Activator) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/hpe-telco-service-activator-vulnerability/

    Post summary

    HPE disclosed a critical Host‑header validation flaw (CVE‑2025‑12543) that allows attackers to bypass access controls; a patch is available via TSA 10.5.0+ and exposure should be restricted.

    0000052
    196 followersView on X
  • Komodo Cyber Security@Komodosec
    General

    #VulnerabilityReport #CachePoisoning The 9.6 Crack in Java’s Foundation: Critical Undertow Flaw CVE-2025-12543 https://securityonline.info/the-9-6-crack-in-javas-foundation-critical-undertow-flaw-cve-2025-12543/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces a new CVE (CVE‑2025‑12543) regarding a critical flaw in Undertow, but offers no further technical details, PoC, exploit, or mitigation information.

    0000063
    1.5K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_apache_camel-spring_boot-
Appredhatdata_grid8.0--
Appredhatfuse7.0.0--
Appredhatjboss_enterprise_application_platform---
Appredhatjboss_enterprise_application_platform---
Appredhatjboss_enterprise_application_platform7.0.0--
Appredhatjboss_enterprise_application_platform_expansion_pack---
Appredhatprocess_automation7.0--
Appredhatsingle_sign-on7.0--
Appredhatundertow---

Explore more