Red HatCVE-2025-12799
Red Hat Jastow: cross-site scripting
Medium6.5CVE-2025-12799 · Published Jul 7, 2026 · updated Jul 29, 2026
A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-79
- www.cve.org/CVERecord?id=CVE-2025-12799
- nvd.nist.gov/vuln/detail/CVE-2025-12799
- access.redhat.com/errata/RHSA-2026:36342
- access.redhat.com/errata/RHSA-2026:36343
- access.redhat.com/errata/RHSA-2026:36344
- access.redhat.com/errata/RHSA-2026:36345
- access.redhat.com/security/cve/CVE-2025-12799
- bugzilla.redhat.com/show_bug.cgi?id=2413071
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 7 | Red Hat GStreamer: incorrect control flow | Low3.7 | No fix yet |
| Jul 7 | Red Hat 389-ds-base: attacker could detect plaintext equality across encrypted | Medium4.4 | No fix yet |
| Jul 7 | Red Hat Directory Server 11: denial of service | Medium5.3 | No fix yet |
| Jul 7 | Red Hat 389-ds-base: buffer overflow | High8.8 | No fix yet |
| Jul 7 | Red Hat SSSD: insecure default | High8.8 | No fix yet |
| Jul 7 | Red Hat SSSD: path traversal | High8.0 | No fix yet |