Eclipse
Eclipse Vert.x: vulnerabilities and CVEs
Eclipse Vert.x has 15 published vulnerabilities, 5 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs15
Last 12 months5
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15076 | High (8.2) | 0.20% | — | Jul 14, 2026 | In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not validate that the Domain attribute of a Set-Cookie response header matches… |
| CVE-2026-15075 | High (8.2) | 0.20% | — | Jul 14, 2026 | In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP 30x redirects. Only… |
| CVE-2026-6860 | Medium (6.9) | 0.31% | — | May 6, 2026 | A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com,… |
| CVE-2025-11966 | Low (2.3) | 0.29% | — | Oct 22, 2025 | In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into generated HTML without proper escaping in the href, title, and link… |
| CVE-2025-11965 | Medium (6.3) | 0.50% | — | Oct 22, 2025 | In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to hidden files fails to restrict access to hidden directories, allowing unauthorized users to retrieve… |
| CVE-2025-49574 | Medium (6.4) | 0.32% | — | Jun 23, 2025 | Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.1, 3.20.2, and 3.15.6, there is a potential data leak when duplicating a duplicated context. Quarkus… |
| CVE-2024-8391 | Medium (6.9) | 0.58% | — | Sep 4, 2024 | In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client). This is fixed in the 4.5.10 version.… |
| CVE-2024-1300 | Medium (5.4) | 1.1% | — | Apr 2, 2024 | A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped… |
| CVE-2024-1023 | Medium (6.5) | 1.7% | — | Mar 27, 2024 | A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering… |
| CVE-2019-17640 | Critical (9.8) | 2.0% | — | Oct 15, 2020 | In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correctly processes back… |
| CVE-2018-12544 | Critical (9.8) | 2.2% | — | Oct 10, 2018 | In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the… |
| CVE-2018-12542 | Critical (9.8) | 2.2% | — | Oct 10, 2018 | In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (forward slashes)… |
| CVE-2018-12541 | Medium (6.5) | 2.7% | — | Oct 10, 2018 | In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a… |
| CVE-2018-12537 | Medium (5.3) | 2.5% | — | Aug 14, 2018 | In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject… |
| CVE-2018-12540 | High (8.8) | 2.0% | — | Jul 12, 2018 | In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.