« Back to list

Eclipse

Eclipse Vert.x: vulnerabilities and CVEs

Eclipse Vert.x has 15 published vulnerabilities, 5 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs15
Last 12 months5
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-15076High (8.2)0.20%—Jul 14, 2026
In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not validate that the Domain attribute of a Set-Cookie response header matches…
CVE-2026-15075High (8.2)0.20%—Jul 14, 2026
In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP 30x redirects. Only…
CVE-2026-6860Medium (6.9)0.31%—May 6, 2026
A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com,…
CVE-2025-11966Low (2.3)0.29%—Oct 22, 2025
In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into generated HTML without proper escaping in the href, title, and link…
CVE-2025-11965Medium (6.3)0.50%—Oct 22, 2025
In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to hidden files fails to restrict access to hidden directories, allowing unauthorized users to retrieve…
CVE-2025-49574Medium (6.4)0.32%—Jun 23, 2025
Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.1, 3.20.2, and 3.15.6, there is a potential data leak when duplicating a duplicated context. Quarkus…
CVE-2024-8391Medium (6.9)0.58%—Sep 4, 2024
In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client). This is fixed in the 4.5.10 version.…
CVE-2024-1300Medium (5.4)1.1%—Apr 2, 2024
A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped…
CVE-2024-1023Medium (6.5)1.7%—Mar 27, 2024
A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering…
CVE-2019-17640Critical (9.8)2.0%—Oct 15, 2020
In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correctly processes back…
CVE-2018-12544Critical (9.8)2.2%—Oct 10, 2018
In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the…
CVE-2018-12542Critical (9.8)2.2%—Oct 10, 2018
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (forward slashes)…
CVE-2018-12541Medium (6.5)2.7%—Oct 10, 2018
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a…
CVE-2018-12537Medium (5.3)2.5%—Aug 14, 2018
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject…
CVE-2018-12540High (8.8)2.0%—Jul 12, 2018
In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application2
  2. T1005 Data from Local System1
  3. T1539 Steal Web Session Cookie1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Eclipse