CVE-2018-12541 - CVE House
Back to Database
Status published Medium CVE-2018-12541

In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the...

Vulnerability Description

In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a reasonnable limit (8192 bytes) above which the WebSocket gets an HTTP response with the 413 status code and the connection gets closed.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-12541

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

The Eclipse Foundation

View all reports →

Affected Software

Eclipse Vert.x
Vulnerable Versions:
3.0, unspecified

Timeline

Official Publish: October 10th, 2018
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.