← Back

CVE-2025-8154

nvd nist
Published: May 11, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities.

Affected (8)

4 products
Api Control Plane
Api Manager
Traffic Manager
Universal Gateway
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 4.5.0 to 4.5.0.21
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 4.1.0 to 4.1.0.218
From 4.2.0 to 4.2.0.164
From 4.3.0 to 4.3.0.74
From 4.4.0 to 4.4.0.38
From 4.5.0 to 4.5.0.20
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
From 4.5.0 to 4.5.0.19
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
From 4.5.0 to 4.5.0.19

References (1)

Timeline

No history available yet.