CVE-2026-15075

HIGH

Eclipse Vert.x - Exposure of Sensitive Information to an Unauthorized Actor

Title source: rule
STIX 2.1

Description

In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP 30x redirects. Only Content-Length is stripped; no origin comparison (scheme, host, port) is performed before copying headers to the redirect target. As a result, credential headers, including Authorization, Cookie, Proxy-Authorization, and arbitrary custom headers such as X-API-Token, are forwarded to the redirect destination without the caller's knowledge. An attacker who can cause a Vert.x HttpClient to issue a request that is redirected to an attacker-controlled host (for example, by supplying a URL to a webhook dispatcher, image proxy, or microservice URL fetcher) can capture bearer tokens, basic-auth credentials, session cookies, and API keys attached to the original request.

Scores

CVSS v3 7.5
EPSS 0.0014
EPSS Percentile 4.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-346
Status published
Products (3)
eclipse/vert.x < 4.5.29
Eclipse Foundation/Eclipse Vert.x 4.0.0 - 4.5.29
Eclipse Foundation/Eclipse Vert.x 5.0.0 - 5.1.4
Published Jul 14, 2026
Tracked Since Jul 14, 2026