CVE-2025-11966 - CVE House
Back to Database
Status published Low CVE-2025-11966

In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when...

Vulnerability Description

In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into generated HTML without proper escaping in the href, title, and link attributes. An attacker who can create or rename files or directories within a served path can craft filenames containing malicious script or HTML content, leading to stored cross-site scripting (XSS) that executes in the context of users viewing the affected directory listing.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11966

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Sho Odagiri

Affected Vendor

Eclipse Foundation

View all reports →

Affected Software

Vert.x
Vulnerable Versions:
4.0.0, 5.0.0

Timeline

Official Publish: October 22nd, 2025
Last Modified: October 22nd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)