CVE-2026-6860

MEDIUM

Eclipse Vert.x 4.3.4-4.5.25, 5.0.0-5.0.10 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com, any XYZ.example.com where xyz is a valid name can be used.

Scores

CVSS v3 5.3
EPSS 0.0001
EPSS Percentile 1.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-295 CWE-770
Status published
Products (7)
eclipse/vert.x 4.3.4 - 4.5.26
Eclipse Foundation/Eclipse Vert.x 4.3.4 - 4.5.26
Eclipse Foundation/Eclipse Vert.x 5.0.0 - 5.0.11
io.vertx/vertx-core 4.3.4 - 4.3.8Maven
io.vertx/vertx-core 4.4.0 - 4.4.9Maven
io.vertx/vertx-core 4.5.0 - 4.5.25Maven
io.vertx/vertx-core 5.0.0 - 5.0.8Maven
Published May 06, 2026
Tracked Since May 06, 2026