By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities.
Project Subscriptions
No advisories yet.
Solution
Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4410/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4410/#solution
Workaround
No workaround given by the vendor.
Mon, 11 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities. | |
| Title | HTTP Header Injection via Webhook API in Multiple WSO2 Products Allows Response Header Manipulation | |
| First Time appeared |
Wso2
Wso2 wso2 Api Control Plane Wso2 wso2 Api Manager Wso2 wso2 Carbon Api Gateway Wso2 wso2 Carbon Api Management Implementation Wso2 wso2 Traffic Manager Wso2 wso2 Universal Gateway |
|
| Weaknesses | CWE-74 | |
| CPEs | cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_carbon_api_gateway:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_carbon_api_management_implementation:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_traffic_manager:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_universal_gateway:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wso2
Wso2 wso2 Api Control Plane Wso2 wso2 Api Manager Wso2 wso2 Carbon Api Gateway Wso2 wso2 Carbon Api Management Implementation Wso2 wso2 Traffic Manager Wso2 wso2 Universal Gateway |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WSO2
Published:
Updated: 2026-05-11T12:43:47.037Z
Reserved: 2025-07-25T06:42:23.104Z
Link: CVE-2025-8154
Updated: 2026-05-11T12:43:43.481Z
Status : Received
Published: 2026-05-11T10:16:12.863
Modified: 2026-05-11T10:16:12.863
Link: CVE-2025-8154
No data.
OpenCVE Enrichment
No data.