CVE-2025-12999

CVE-2025-12999 published: UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a trusted proxy, falling bac...

View full NVD advisory → ← Back to CVE watch