In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses.
By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities.
References
| Link | Resource |
|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4410/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
27 May 2026, 19:42
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Wso2 universal Gateway
Wso2 traffic Manager Wso2 api Manager Wso2 api Control Plane Wso2 |
|
| CPE | cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:* |
|
| References | () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4410/ - Vendor Advisory |
11 May 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-11 10:16
Updated : 2026-05-27 19:42
NVD link : CVE-2025-8154
Mitre link : CVE-2025-8154
CVE.ORG link : CVE-2025-8154
JSON object : View
Products Affected
wso2
- universal_gateway
- traffic_manager
- api_control_plane
- api_manager
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
