SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-15075

HIGH · CVSS 7.5 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Eclipse Vert.x versions up to 4.5.29 and 5.1.4 are vulnerable due to the DefaultRedirectHandler improperly propagating all request headers during cross-origin HTTP 30x redirects, exposing sensitive information such as Authorization and Cookie headers to potentially malicious redirect targets. This vulnerability allows attackers to capture credentials and tokens if they can manipulate the redirect URL. Organizations using affected versions of Vert.x should prioritize patching to mitigate the risk of credential leakage.

CVE
CVE-2026-15075
Severity
HIGH
CVSS
7.5
EPSS
0.14%

Original NVD Description

In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP 30x redirects. Only Content-Length is stripped; no origin comparison (scheme, host, port) is performed before copying headers to the redirect target. As a result, credential headers, including Authorization, Cookie, Proxy-Authorization, and arbitrary custom headers such as X-API-Token, are forwarded to the redirect destination without the caller's knowledge. An attacker who can cause a Vert.x HttpClient to issue a request that is redirected to an attacker-controlled host (for example, by supplying a URL to a webhook dispatcher, image proxy, or microservice URL fetcher) can capture bearer tokens, basic-auth credentials, session cookies, and API keys attached to the original request.

Related CVEs

Other vulnerabilities affecting the same vendor(s)