CVE-2026-6860
MEDIUMEclipse Vert.x 4.3.4-4.5.25, 5.0.0-5.0.10 - Improper Certificate Validation
Title source: llmDescription
A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com, any XYZ.example.com where xyz is a valid name can be used.
Scores
CVSS v3
5.3
EPSS
0.0001
EPSS Percentile
1.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-295
CWE-770
Status
published
Products (7)
eclipse/vert.x
4.3.4 - 4.5.26
Eclipse Foundation/Eclipse Vert.x
4.3.4 - 4.5.26
Eclipse Foundation/Eclipse Vert.x
5.0.0 - 5.0.11
io.vertx/vertx-core
4.3.4 - 4.3.8Maven
io.vertx/vertx-core
4.4.0 - 4.4.9Maven
io.vertx/vertx-core
4.5.0 - 4.5.25Maven
io.vertx/vertx-core
5.0.0 - 5.0.8Maven
Published
May 06, 2026
Tracked Since
May 06, 2026