CVE-2026-6860: Eclipse Vert.x

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com, any XYZ.example.com where xyz is a valid name can be used.

Affected products

  • Eclipse Vert.x: from 4.3.4, up to and including 4.5.26; from 5.0.0, up to and including 5.0.11

Published 2026-05-06. Last modified 2026-06-17.