Executive brief
Eclipse Vert.x is a toolkit for building reactive applications on the Java Virtual Machine. A security flaw in its Web Client component allows a malicious server to 'plant' cookies for other, unrelated websites. If an application using this library connects to a server controlled by an attacker, the attacker can force the application to send the attacker's session information to a legitimate third-party service (like a payment processor), potentially allowing the attacker to capture sensitive transaction data or hijack the user's interaction with that service.
Technical details
A vulnerability exists in the WebClientSession component of Eclipse Vert.x Web Client (versions up to 4.5.29 and 5.1.4) due to improper origin validation (CWE-346). The component fails to verify that the 'Domain' attribute in a 'Set-Cookie' response header matches the domain of the originating server, violating RFC 6265. An attacker controlling a server contacted by the victim application can inject cookies scoped to any third-party domain. When the application later communicates with that targeted domain using the same session, it transmits the attacker-controlled cookie. This can lead to session fixation or account shadowing, where the victim's requests (potentially containing sensitive API payloads or payment data) are processed under the attacker's session context on the target service.
Affected products
- Eclipse Foundation Eclipse Vert.x Web Client <= 4.5.29, <= 5.1.4
Timeline
- 2026-07-14: advisory: NVD publication date