CVE-2025-12999 | Eclipse Open VSX up to 1.1.2 UrlUtil UrlUtil.getBaseUrl input validation
A vulnerability marked as problematic has been reported in Eclipse Open VSX up to 1.1.2. Impacted is the function UrlUtil.getBaseUrl of the component UrlUtil. The manipulation of the argument X-Forwarded-Host/X-Forwarded-Proto/X-Forwarded-Prefix leads to improper input validation.
This vulnerability is listed as CVE-2025-12999. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More