Eclipse Vert.x Web static handler file access denial
Published Jan 15, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.39%
Description
The Vert.x Web static handler component cache can be manipulated to deny the access to static files served by the handler using specifically crafted request URI.
The issue comes from an improper implementation of the C. rule of section 5.2.4 of RFC3986 and is fixed in Vert.x Core component (used by Vert.x Web): https://github.com/eclipse-vertx/vert.x/pull/5895
Steps to reproduce Given a file served by the static handler, craft an URI that introduces a string like bar%2F..%2F after the last / char to deny the access to the URI with an HTTP 404 response. For example https://example.com/foo/index.html can be denied with https://example.com/foo/bar%2F..%2Findex.html
Mitgation Disabling Static Handler cache fixes the issue.
StaticHandler staticHandler = StaticHandler.create().setCachingEnabled(false);
Affected products
-
- Version 4.0.0StatusaffectedConstraints<=4.5.23
- Version 5.0.0StatusaffectedConstraints<=5.0.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Eclipse Vert.x | Eclipse Vert.x | unaffected |
|
- ≥ 4.0.0 · ≤ 4.5.23
- ≥ 5.0.0 · ≤ 5.0.6
No data.
Cryostat 4 on RHEL 9
cryostat/cryostat-reports-rhel9:4.2.0-9
Fixed · RHSA-2026:17789
Cryostat 4 on RHEL 9
cryostat/cryostat-rhel9:4.2.0-9
Fixed · RHSA-2026:17789
Cryostat 4 on RHEL 9
cryostat/jfr-datasource-rhel9:4.2.0-9
Fixed · RHSA-2026:17789
HawtIO HawtIO 4.4.0
vertx-core
Fixed · RHSA-2026:25089
Red Hat Build of Apache Camel 4.14 for Quarkus 3.27
vertx-core
Fixed · RHSA-2026:8159
Red Hat JBoss EAP XP 5.0 Update 4.0
vertx-core
Fixed · RHSA-2026:3951
Red Hat JBoss EAP XP 6.0 Update 3.0
vertx-core
Fixed · RHSA-2026:5482
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-wildfly-0:7.3.18-3.GA_redhat_00001.1.el7eap
Fixed · RHSA-2026:33371
Red Hat OpenShift AI 2.25
rhoai/odh-trustyai-service-rhel9:1776748859
Fixed · RHSA-2026:10184
Red Hat OpenShift Dev Spaces 3.27
devspaces/server-rhel9:1774228740
Fixed · RHSA-2026:6192
Red Hat build of Apache Camel 4.14.4 for Spring Boot 3.5.11
vertx-core
Fixed · RHSA-2026:3890
Red Hat build of Quarkus 3.20.6
vertx-core
Fixed · RHSA-2026:7109
Red Hat build of Quarkus 3.27.3
vertx-core
Fixed · RHSA-2026:7380
Streams for Apache Kafka 2.9.4
vertx-core
Fixed · RHSA-2026:34608
Streams for Apache Kafka 3.2.0
vertx-core
Fixed · RHSA-2026:13571
Streams for Apache Kafka 3.2.0
vertx-core-logging
Fixed · RHSA-2026:13571
OpenShift Serverless
openshift-serverless-1/kn-ekb-dispatcher-rhel9
Will not fix
OpenShift Serverless
openshift-serverless-1/kn-ekb-receiver-rhel9
Will not fix
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-ddb-streams-source-rhel9
Will not fix
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-s3-sink-rhel9
Will not fix
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-s3-source-rhel9
Will not fix
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-sns-sink-rhel9
Will not fix
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-sqs-sink-rhel9
Will not fix
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-sqs-source-rhel9
Will not fix
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-log-sink-rhel9
Will not fix
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-timer-source-rhel9
Will not fix
Red Hat Data Grid 8
vertx-core
Not affected
Red Hat Enterprise Linux 10
moditect
Not affected
Red Hat Enterprise Linux 8
pki-core:10.6/resteasy
Not affected
Red Hat Enterprise Linux 8
pki-deps:10.6/resteasy
Not affected
Red Hat Enterprise Linux 9
resteasy
Not affected
Red Hat Fuse 7
vertx-core
Will not fix
Red Hat JBoss Enterprise Application Platform 7
vertx-core
Not affected
Red Hat JBoss Enterprise Application Platform 8
vertx-core
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
vertx-core
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-trustyai-service-rhel8
Not affected
Red Hat Process Automation 7
vertx-core
Will not fix
Red Hat build of Apache Camel 4 for Quarkus 3
vertx-core
Affected
Red Hat build of Apicurio Registry 2
vertx-core
Will not fix
Red Hat build of Apicurio Registry 3
vertx-core
Affected
Red Hat build of Debezium 2
vertx-core
Will not fix
Red Hat build of Debezium 3
vertx-core
Will not fix
Red Hat build of OptaPlanner 8
vertx-core
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Cryostat 4 on RHEL 9 | cryostat/cryostat-reports-rhel9:4.2.0-9 | Fixed | RHSA-2026:17789 |
| Cryostat 4 on RHEL 9 | cryostat/cryostat-rhel9:4.2.0-9 | Fixed | RHSA-2026:17789 |
| Cryostat 4 on RHEL 9 | cryostat/jfr-datasource-rhel9:4.2.0-9 | Fixed | RHSA-2026:17789 |
| HawtIO HawtIO 4.4.0 | vertx-core | Fixed | RHSA-2026:25089 |
| Red Hat Build of Apache Camel 4.14 for Quarkus 3.27 | vertx-core | Fixed | RHSA-2026:8159 |
| Red Hat JBoss EAP XP 5.0 Update 4.0 | vertx-core | Fixed | RHSA-2026:3951 |
| Red Hat JBoss EAP XP 6.0 Update 3.0 | vertx-core | Fixed | RHSA-2026:5482 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-wildfly-0:7.3.18-3.GA_redhat_00001.1.el7eap | Fixed | RHSA-2026:33371 |
| Red Hat OpenShift AI 2.25 | rhoai/odh-trustyai-service-rhel9:1776748859 | Fixed | RHSA-2026:10184 |
| Red Hat OpenShift Dev Spaces 3.27 | devspaces/server-rhel9:1774228740 | Fixed | RHSA-2026:6192 |
| Red Hat build of Apache Camel 4.14.4 for Spring Boot 3.5.11 | vertx-core | Fixed | RHSA-2026:3890 |
| Red Hat build of Quarkus 3.20.6 | vertx-core | Fixed | RHSA-2026:7109 |
| Red Hat build of Quarkus 3.27.3 | vertx-core | Fixed | RHSA-2026:7380 |
| Streams for Apache Kafka 2.9.4 | vertx-core | Fixed | RHSA-2026:34608 |
| Streams for Apache Kafka 3.2.0 | vertx-core | Fixed | RHSA-2026:13571 |
| Streams for Apache Kafka 3.2.0 | vertx-core-logging | Fixed | RHSA-2026:13571 |
| OpenShift Serverless | openshift-serverless-1/kn-ekb-dispatcher-rhel9 | Will not fix | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-ekb-receiver-rhel9 | Will not fix | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-ddb-streams-source-rhel9 | Will not fix | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-s3-sink-rhel9 | Will not fix | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-s3-source-rhel9 | Will not fix | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-sns-sink-rhel9 | Will not fix | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-sqs-sink-rhel9 | Will not fix | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-sqs-source-rhel9 | Will not fix | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-log-sink-rhel9 | Will not fix | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-timer-source-rhel9 | Will not fix | n/a |
| Red Hat Data Grid 8 | vertx-core | Not affected | n/a |
| Red Hat Enterprise Linux 10 | moditect | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Not affected | n/a |
| Red Hat Enterprise Linux 9 | resteasy | Not affected | n/a |
| Red Hat Fuse 7 | vertx-core | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | vertx-core | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | vertx-core | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | vertx-core | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-trustyai-service-rhel8 | Not affected | n/a |
| Red Hat Process Automation 7 | vertx-core | Will not fix | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | vertx-core | Affected | n/a |
| Red Hat build of Apicurio Registry 2 | vertx-core | Will not fix | n/a |
| Red Hat build of Apicurio Registry 3 | vertx-core | Affected | n/a |
| Red Hat build of Debezium 2 | vertx-core | Will not fix | n/a |
| Red Hat build of Debezium 3 | vertx-core | Will not fix | n/a |
| Red Hat build of OptaPlanner 8 | vertx-core | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability allows a remote attacker to block access to specific static files, such as images, CSS or HTML files. However, the underlying Vert.x server, the API endpoints and other non-cached resources are not affected. Due to this reason, this issue has been rated with a moderate severity.
Red Hat mitigation
To mitigate this vulnerability, consider disabling the static handler cache by configuring the StaticHandler instance with setCachingEnabled(false), for example: ~~~ StaticHandler staticHandler = StaticHandler.create().setCachingEnabled(false); ~~~
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jan 15, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Jan–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.39% (0.00390) | 30.74th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.34% (0.00343) | 25.91th | v5 (v2026.06.15) |
| Jan 16, 2026 | 0.04% (0.00040) | 11.97th | v4 (v2025.03.14) |
References (10)
- https://access.redhat.com/security/cve/CVE-2026-1002 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2430180 Issue Tracking
- https://github.com/advisories/GHSA-cphf-4846-3xx9 Advisory
- https://github.com/eclipse-vertx/vert.x/commit/5b67f5d17788b2483d277c760f3f8154f9b2fed0
- https://github.com/eclipse-vertx/vert.x/commit/d007e7b418543eb1567fe95cf20f5450a5c2d047
- https://github.com/eclipse-vertx/vert.x/pull/5894
- https://github.com/eclipse-vertx/vert.x/pull/5895 patchIssue Tracking
- https://github.com/vert-x3/vertx-web/issues/2836 exploit
- https://nvd.nist.gov/vuln/detail/CVE-2026-1002
- https://www.cve.org/CVERecord?id=CVE-2026-1002
Change history (0)
No recorded changes yet.