CVE-2025-8154: WSO2 API Control Plane

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can lead to various adverse effects, including the manipulation of browser caching, alteration of security-related headers, and the injection of sensitive information such as cookie values, potentially enabling session hijacking or other malicious activities.

Affected products

  • WSO2 API Control Plane: from 4.5.0, before 4.5.0.21 (fixed in 4.5.0.21)
  • WSO2 API Manager: from 4.1.0, before 4.1.0.218 (fixed in 4.1.0.218); from 4.2.0, before 4.2.0.164 (fixed in 4.2.0.164); from 4.3.0, before 4.3.0.74 (fixed in 4.3.0.74); from 4.4.0, before 4.4.0.38 (fixed in 4.4.0.38); from 4.5.0, before 4.5.0.20 (fixed in 4.5.0.20)
  • WSO2 Traffic Manager: from 4.5.0, before 4.5.0.19 (fixed in 4.5.0.19)
  • WSO2 Universal Gateway: from 4.5.0, before 4.5.0.19 (fixed in 4.5.0.19)

Published 2026-05-11. Last modified 2026-06-17.