CVE Database
/

CVE-2025-8154

Back to search

CVE-2025-8154

Published: May 11, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

5.3

MEDIUM

Description

In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities.

VendorProductVersions

WSO2

WSO2 API Manager

unknown
0 - < 4.1.0
affected
4.1.0 - < 4.1.0.218
affected
4.2.0 - < 4.2.0.164
affected
4.3.0 - < 4.3.0.74
affected
4.4.0 - < 4.4.0.38

+1 more versions

WSO2

WSO2 Universal Gateway

affected
4.5.0 - < 4.5.0.19

WSO2

WSO2 Traffic Manager

affected
4.5.0 - < 4.5.0.19

WSO2

WSO2 API Control Plane

affected
4.5.0 - < 4.5.0.21

WSO2

WSO2 Carbon API Gateway

affected
9.20.74 - < 9.20.74.374
affected
9.28.116 - < 9.28.116.363
affected
9.29.120 - < 9.29.120.181
affected
9.30.67 - < 9.30.67.104
affected
9.31.86 - < 9.31.86.64

+1 more versions

WSO2

WSO2 Carbon API Management Implementation

affected
9.20.74 - < 9.20.74.374
affected
9.28.116 - < 9.28.116.363
affected
9.29.120 - < 9.29.120.181
affected
9.30.67 - < 9.30.67.104
affected
9.31.86 - < 9.31.86.64

+1 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now