In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into generated HTML without proper escaping in the href, title, and link attributes. An attacker who can create or rename files or directories within a served path can craft filenames containing malicious script or HTML content, leading to stored cross-site scripting (XSS) that executes in the context of users viewing the affected directory listing.
References
| Link | Resource |
|---|---|
| https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/303 | Exploit Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
17 Jun 2026, 08:31
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/303 - Exploit, Issue Tracking, Vendor Advisory |
20 Jan 2026, 19:31
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:eclipse:vert.x:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.4 |
| First Time |
Eclipse vert.x
Eclipse |
|
| References | () https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/303 - Issue Tracking, Vendor Advisory, Exploit |
22 Oct 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-22 15:15
Updated : 2026-06-17 08:31
NVD link : CVE-2025-11966
Mitre link : CVE-2025-11966
CVE.ORG link : CVE-2025-11966
JSON object : View
Products Affected
eclipse
- vert.x
