In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses.
By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities.
Metrics
Affected Vendors & Products
References
History
Mon, 11 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities. | |
| Title | HTTP Header Injection via Webhook API in Multiple WSO2 Products Allows Response Header Manipulation | |
| First Time appeared |
Wso2
Wso2 wso2 Api Control Plane Wso2 wso2 Api Manager Wso2 wso2 Carbon Api Gateway Wso2 wso2 Carbon Api Management Implementation Wso2 wso2 Traffic Manager Wso2 wso2 Universal Gateway |
|
| Weaknesses | CWE-74 | |
| CPEs | cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_carbon_api_gateway:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_carbon_api_management_implementation:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_traffic_manager:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_universal_gateway:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wso2
Wso2 wso2 Api Control Plane Wso2 wso2 Api Manager Wso2 wso2 Carbon Api Gateway Wso2 wso2 Carbon Api Management Implementation Wso2 wso2 Traffic Manager Wso2 wso2 Universal Gateway |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WSO2
Published:
Updated: 2026-05-11T12:43:47.037Z
Reserved: 2025-07-25T06:42:23.104Z
Link: CVE-2025-8154
Updated: 2026-05-11T12:43:43.481Z
Status : Received
Published: 2026-05-11T10:16:12.863
Modified: 2026-05-11T10:16:12.863
Link: CVE-2025-8154
No data.
OpenCVE Enrichment
Updated: 2026-05-11T17:45:26Z