In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2018-0516 | In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response. |
![]() |
GHSA-6cw8-7j6c-hccp | Moderate severity vulnerability that affects io.vertx:vertx-core |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-05T08:38:06.072Z
Reserved: 2018-06-18T00:00:00
Link: CVE-2018-12537

No data.

Status : Modified
Published: 2018-08-14T19:29:00.247
Modified: 2024-11-21T03:45:23.467
Link: CVE-2018-12537


No data.