LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-15076

eclipse · vert.x

Published
CVSS7.5
Severityhigh
WeaknessCWE-346
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not validate that the Domain attribute of a Set-Cookie response header matches the originating server's domain, in violation of RFC 6265 section 5.3. An attacker who controls any server that the victim application contacts can inject a cookie scoped to an arbitrary third-party domain; because the session store performs no cross-domain ownership check, it stores and later transmits that cookie to the targeted domain. When the victim application subsequently sends a request to the targeted domain using the same WebClientSession, it presents the attack

References

← Back to the CVE Tracker

Our coverage of CVE-2026-15076

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-15076.