Red Hat Security Advisory: Red Hat Build of Apache Camel 4.14.4 for Spring Boot release.
A security update for Red Hat JBoss Enterprise Application Platform 8.1 addresses multiple vulnerabilities including CVE-2025-12543, where the Undertow HTTP server fails to reject malformed Host headers, potentially leading to cache poisoning and server-side request forgery (SSRF). The update also fixes other vulnerabilities such as an OutOfMemory issue when parsing form data and an HTTP/2 DDoS vulnerability. The update is available for Red Hat JBoss Enterprise Application Platform 8.1 on Red Hat Enterprise Linux 8 and 9. Users are advised to apply the update to mitigate these issues.
AI Analysis
Technical Summary
The Red Hat JBoss Enterprise Application Platform 8.1.3 update includes security fixes for the Undertow HTTP server component. Notably, CVE-2025-12543 addresses a vulnerability where malformed Host headers are not properly rejected, which could lead to cache poisoning and SSRF attacks. Additional fixes include resolving an OutOfMemory condition during form data parsing (CVE-2024-3884) and mitigating an HTTP/2 DDoS vulnerability (CVE-2025-9784). The update upgrades several components including Undertow, Hibernate ORM, WildFly Elytron, and others to patched versions. This advisory covers Red Hat JBoss Enterprise Application Platform 8.1 for Red Hat Enterprise Linux versions 8 and 9.
Potential Impact
Successful exploitation of CVE-2025-12543 could allow an attacker to poison caches or perform server-side request forgery via malformed Host headers. Other addressed vulnerabilities include potential denial of service via OutOfMemory conditions and HTTP/2 DDoS attacks. These issues could impact the availability and integrity of applications running on the affected platform.
Mitigation Recommendations
Red Hat has released version 8.1.3 of JBoss Enterprise Application Platform 8.1 for Red Hat Enterprise Linux 8 and 9, which includes fixes for these vulnerabilities. Users should apply this update after ensuring all prior relevant errata are installed and backing up their systems. Detailed update instructions are available from Red Hat's official documentation. No additional mitigation steps are indicated beyond applying the official patch.
Red Hat Security Advisory: Red Hat Build of Apache Camel 4.14.4 for Spring Boot release.
Description
A security update for Red Hat JBoss Enterprise Application Platform 8.1 addresses multiple vulnerabilities including CVE-2025-12543, where the Undertow HTTP server fails to reject malformed Host headers, potentially leading to cache poisoning and server-side request forgery (SSRF). The update also fixes other vulnerabilities such as an OutOfMemory issue when parsing form data and an HTTP/2 DDoS vulnerability. The update is available for Red Hat JBoss Enterprise Application Platform 8.1 on Red Hat Enterprise Linux 8 and 9. Users are advised to apply the update to mitigate these issues.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat JBoss Enterprise Application Platform 8.1.3 update includes security fixes for the Undertow HTTP server component. Notably, CVE-2025-12543 addresses a vulnerability where malformed Host headers are not properly rejected, which could lead to cache poisoning and SSRF attacks. Additional fixes include resolving an OutOfMemory condition during form data parsing (CVE-2024-3884) and mitigating an HTTP/2 DDoS vulnerability (CVE-2025-9784). The update upgrades several components including Undertow, Hibernate ORM, WildFly Elytron, and others to patched versions. This advisory covers Red Hat JBoss Enterprise Application Platform 8.1 for Red Hat Enterprise Linux versions 8 and 9.
Potential Impact
Successful exploitation of CVE-2025-12543 could allow an attacker to poison caches or perform server-side request forgery via malformed Host headers. Other addressed vulnerabilities include potential denial of service via OutOfMemory conditions and HTTP/2 DDoS attacks. These issues could impact the availability and integrity of applications running on the affected platform.
Mitigation Recommendations
Red Hat has released version 8.1.3 of JBoss Enterprise Application Platform 8.1 for Red Hat Enterprise Linux 8 and 9, which includes fixes for these vulnerabilities. Users should apply this update after ensuring all prior relevant errata are installed and backing up their systems. Detailed update instructions are available from Red Hat's official documentation. No additional mitigation steps are indicated beyond applying the official patch.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:3890
- Cve Count
- 4
- Additional Cves
- ["CVE-2026-1002","CVE-2026-27727","CVE-2026-27830"]
- Cvss Version
- null
Threat ID: 6a160984e29bf47b50650c4a
Added to database: 05/26/2026, 20:58:44 UTC
Last enriched: 08/03/2026, 22:20:41 UTC
Last updated: 08/03/2026, 22:20:41 UTC
Views: 107
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.