Eclipse / Eclipse Vert.x
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-15075 | vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects | HIGH | 8.2 | Jul 14, 2026 |
| CVE-2026-15076 | io.vertx/vertx-web: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation | HIGH | 8.2 | Jul 14, 2026 |
| CVE-2026-6860 | eclipse-vertx/vert.x: eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name | MEDIUM | 6.9 | May 6, 2026 |
| CVE-2024-8391 | Eclipse Vert.x gRPC server does not limit the maximum message size | MEDIUM | 6.9 | Sep 4, 2024 |
| CVE-2019-17640 | In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.… | CRITICAL | 9.8 | Oct 15, 2020 |
| CVE-2018-12544 | vertx: API Validation XML Schemas do not forbid file system access | CRITICAL | 9.8 | Oct 10, 2018 |
| CVE-2018-12542 | In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, b… | CRITICAL | 9.8 | Oct 10, 2018 |
| CVE-2018-12541 | vertx: WebSocket HTTP upgrade implementation holds the entire http request in memory before the handshake | MEDIUM | 6.5 | Oct 10, 2018 |
| CVE-2018-12537 | vertx: Improper neutralization of CRLF sequences allows remote attackers to inject arbitrary HTTP response headers | MEDIUM | 5.3 | Aug 14, 2018 |
| CVE-2018-12540 | vertx-web: Incomplete CSRF validation by CSRFHandler | HIGH | 8.8 | Jul 12, 2018 |
Showing 1 to 10 of 10 CVEs