CVE-2025-8154

In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*

History

27 May 2026, 19:42

Type Values Removed Values Added
First Time Wso2 universal Gateway
Wso2 traffic Manager
Wso2 api Manager
Wso2 api Control Plane
Wso2
CPE cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*
References () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4410/ - () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4410/ - Vendor Advisory

11 May 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-11 10:16

Updated : 2026-05-27 19:42


NVD link : CVE-2025-8154

Mitre link : CVE-2025-8154

CVE.ORG link : CVE-2025-8154


JSON object : View

Products Affected

wso2

  • universal_gateway
  • traffic_manager
  • api_control_plane
  • api_manager
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')