CVE-2025-8154: HTTP Header Injection via Webhook API in Multiple WSO2 Products Allows Response Header Manipulation
In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses.
By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8154?
The severity of CVE-2025-8154 is rated high with a CVSS score of 7.5.
What type of attack does CVE-2025-8154 facilitate?
CVE-2025-8154 facilitates HTTP header injection attacks through the Webhook API in various WSO2 products.
How can I protect my systems from CVE-2025-8154?
To protect against CVE-2025-8154, implement proper validation and sanitization of user-supplied input for HTTP request headers.
Which WSO2 products are affected by CVE-2025-8154?
CVE-2025-8154 affects WSO2 API Manager, WSO2 Api Control Plane, WSO2 Traffic Manager, and WSO2 Universal Gateway.
What is the impact of exploiting CVE-2025-8154?
Exploiting CVE-2025-8154 allows a malicious actor to inject or overwrite arbitrary HTTP response headers.