7.5

CVE-2025-8154

HTTP Header Injection via Webhook API in Multiple WSO2 Products Allows Response Header Manipulation

In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses.

By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wso2Api Control Plane Version >= 4.5.0 < 4.5.0.21
Wso2Api Manager Version >= 4.1.0 < 4.1.0.218
Wso2Api Manager Version >= 4.2.0 < 4.2.0.164
Wso2Api Manager Version >= 4.3.0 < 4.3.0.74
Wso2Api Manager Version >= 4.4.0 < 4.4.0.38
Wso2Api Manager Version >= 4.5.0 < 4.5.0.20
Wso2Traffic Manager Version >= 4.5.0 < 4.5.0.19
Wso2Universal Gateway Version >= 4.5.0 < 4.5.0.19
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.082
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
ed10eef1-636d-4fbe-9993-6890dfa878f8 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4410/
Vendor Advisory