CVE-2025-12543 | Undertow Header Host server-side request forgery (Nessus ID 282346 / WID-SEC-2026-0054)
A vulnerability identified as critical has been detected in Undertow. Affected by this issue is some unknown functionality of the component Header Handler. This manipulation of the argument Host causes server-side request forgery.
This vulnerability is handled as CVE-2025-12543. The attack can be initiated remotely. There is not any exploit available.