VYPR

Vert.x Web Client

by Eclipse

CVEs (1)

  • CVE-2026-15076HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.00

    In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not validate that the Domain attribute of a Set-Cookie response header matches the originating server's domain, in violation of RFC 6265…