- Description
- In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities.
- Source
- ed10eef1-636d-4fbe-9993-6890dfa878f8
- NVD status
- Analyzed
- Products
- api_control_plane, api_manager, traffic_manager, universal_gateway
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity
- HIGH
- ed10eef1-636d-4fbe-9993-6890dfa878f8
- CWE-74
- Hype score
- Not currently trending
CVE-2025-8154 In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to … https://t.co/z2Ouil8H2d
@CVEnew
11 May 2026
177 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-8154 HTTP Response Header Injection in Webhook API Invocations via Unvalidated Input https://t.co/ZC4tEdKhBz
@VulmonFeeds
11 May 2026
182 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CE735A8B-2A1F-4246-99E3-BD902B7E2AAD",
"versionEndExcluding": "4.5.0.21",
"versionStartIncluding": "4.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EBA7D0D1-7495-4B08-98C1-0CA4FCF133AD",
"versionEndExcluding": "4.1.0.218",
"versionStartIncluding": "4.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C398A7BE-719C-40CB-96A3-86E1FB4FFB6D",
"versionEndExcluding": "4.2.0.164",
"versionStartIncluding": "4.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "4BA261C3-1ACF-489F-8F6F-B5A9A9D9831E",
"versionEndExcluding": "4.3.0.74",
"versionStartIncluding": "4.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "953433E1-3246-44A9-8DE0-370B975ACCDC",
"versionEndExcluding": "4.4.0.38",
"versionStartIncluding": "4.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "01B82174-1DDC-409E-8E96-8A738082AFE9",
"versionEndExcluding": "4.5.0.20",
"versionStartIncluding": "4.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B9F8FDD0-B770-4532-B92F-145B525CAD36",
"versionEndExcluding": "4.5.0.19",
"versionStartIncluding": "4.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D92DFBC5-E71A-4C58-B63C-96110F5CB2ED",
"versionEndExcluding": "4.5.0.19",
"versionStartIncluding": "4.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]