{"id":"CVE-2026-6860","aliases":["GHSA-3g76-f9xq-8vp6"],"url":"https://o3.security/vulnerability/CVE-2026-6860","summary":"Vert.x has a DoS via unbounded server-side SNI SslContext cache growth","details":"A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com, any XYZ.example.com where xyz is a valid name can be used.","published":"2026-05-06T09:55:12.531Z","modified":"2026-08-12T03:51:48.165601613Z","cvss":null,"epss":{"score":0.00238,"percentile":0.14528,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"io.vertx:vertx-core","fixedVersion":null},{"ecosystem":"Maven","name":"io.vertx:vertx-core","fixedVersion":null},{"ecosystem":"Maven","name":"io.vertx:vertx-core","fixedVersion":"4.5.27"},{"ecosystem":"Maven","name":"io.vertx:vertx-core","fixedVersion":"5.0.12"}],"fix":{"url":"https://github.com/eclipse-vertx/vert.x/pull/6102","label":"eclipse-vertx/vert.x#6102"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6860.json"},{"type":"ADVISORY","url":"https://github.com/eclipse-vertx/vert.x/security/advisories/GHSA-3g76-f9xq-8vp6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6860"},{"type":"REPORT","url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/381"},{"type":"FIX","url":"https://github.com/eclipse-vertx/vert.x/pull/6102"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.165601613Z"}}