Skip to content

[UNDERTOW-2656] CVE-2025-12543 Add handler to scrutinize Host header …#1857

Merged
fl4via merged 2 commits into
undertow-io:mainfrom
fl4via:UNDERTOW-2656
Jan 9, 2026
Merged

[UNDERTOW-2656] CVE-2025-12543 Add handler to scrutinize Host header …#1857
fl4via merged 2 commits into
undertow-io:mainfrom
fl4via:UNDERTOW-2656

Conversation

@fl4via

@fl4via fl4via commented Jan 9, 2026

Copy link
Copy Markdown
Member

…in request. Fix NetworkUtils regex patterns to have proper range and include embedded adr

Jira: https://issues.redhat.com/browse/UNDERTOW-2656

2.2.x PR: #1882
2.3.x PR: #1860
2.4.x PR: #1894

…in request. Fix NetworkUtils regex patterns to have proper range and include embedded adr

Signed-off-by: Flavia Rainone <frainone@redhat.com>
@fl4via fl4via added bug fix Contains bug fix(es) waiting CI check Ready to be merged but waiting for CI check labels Jan 9, 2026
Signed-off-by: Flavia Rainone <frainone@redhat.com>
@fl4via fl4via added next release This PR will be merged before next release or has already been merged (for payload double check) and removed waiting CI check Ready to be merged but waiting for CI check labels Jan 9, 2026
@fl4via fl4via merged commit f0cb26c into undertow-io:main Jan 9, 2026
43 checks passed
@fl4via fl4via deleted the UNDERTOW-2656 branch January 9, 2026 14:49
@rodrigoserracoelho

Copy link
Copy Markdown

@fl4via Hello, do you know when 2.4.0 will be in Final version? Thanks.

@tmurakam

Copy link
Copy Markdown

@fl4via When will you update the 2.2.x?
I need to update some my project which using 2.2.x.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug fix Contains bug fix(es)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants