SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2025-12799

MEDIUM · CVSS 6.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

Jastow is susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper input handling when configured to allow unescaped characters in URLs alongside embedded Undertow. This flaw could enable attackers to inject malicious scripts, potentially compromising user data and session integrity. Organizations utilizing Jastow with the specified configuration should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2025-12799
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%

Original NVD Description

A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.