Junglewise Threat Intelligence

CVE-2026-6860: Eclipse Vert.x DoS via unbounded SNI SslContext cache growth

CVE-2026-6860 · Severity: medium · CVSS 5.3 · Published 2026-05-06

Vendors: Eclipse, Eclipse Foundation.

Executive brief

Eclipse Vert.x, a toolkit for building reactive applications on the JVM, is vulnerable to a denial-of-service attack. An unauthenticated attacker can send a large number of specially crafted connection requests that cause the server to consume excessive memory. This can eventually lead to the application crashing or becoming unresponsive, disrupting business operations.

Technical details

A resource exhaustion vulnerability exists in Vert.x TLS handling when server-side SNI is enabled with broad or wildcard hostname mappings. The vulnerability is caused by the use of `computeIfAbsent` in a cache keyed by the SNI server name, which allows an unauthenticated remote attacker to trigger unbounded cache growth by sending many distinct matching SNI names. This leads to excessive memory consumption and a potential Denial of Service (DoS). The issue affects multiple components across different versions, including SSLHelper, SslChannelProvider, and SslContextProvider. Patches are available in versions 4.5.27 and 5.0.12.

Affected products

  • Eclipse Vert.x 4.3.4 - 4.3.8, 4.4.0 - 4.4.9, 4.5.0 - 4.5.26, 5.0.0 - 5.0.11

Timeline

  • 2026-05-06: disclosed
  • 2026-05-09: advisory

References

Related threats