Description
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0516 | In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response. |
Github GHSA |
GHSA-6cw8-7j6c-hccp | Moderate severity vulnerability that affects io.vertx:vertx-core |
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-05T08:38:06.072Z
Reserved: 2018-06-18T00:00:00.000Z
Link: CVE-2018-12537
No data.
Status : Modified
Published: 2018-08-14T19:29:00.247
Modified: 2024-11-21T03:45:23.467
Link: CVE-2018-12537
OpenCVE Enrichment
No data.
EUVD
Github GHSA