CVE-2025-8154

In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-11 10:16

Updated : 2026-06-17 10:06


NVD link : CVE-2025-8154

Mitre link : CVE-2025-8154

CVE.ORG link : CVE-2025-8154


JSON object : View

Products Affected

wso2

  • api_control_plane
  • traffic_manager
  • api_manager
  • universal_gateway
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')