CVE-2025-8154
Description
In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| wso2 | api_control_plane | {"startIncluding":"4.5.0","endExcluding":"4.5.0.21"} | 4.5.0.21 |
| wso2 | api_manager | {"startIncluding":"4.1.0","endExcluding":"4.1.0.218"} | 4.1.0.218 |
| wso2 | traffic_manager | {"startIncluding":"4.5.0","endExcluding":"4.5.0.19"} | 4.5.0.19 |
| wso2 | universal_gateway | {"startIncluding":"4.5.0","endExcluding":"4.5.0.19"} | 4.5.0.19 |
References
CWEs
CWE-74
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.