A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com, any XYZ.example.com where xyz is a valid name can be used.
References
| Link | Resource |
|---|---|
| https://github.com/eclipse-vertx/vert.x/pull/6102 | Issue Tracking Patch |
| https://github.com/eclipse-vertx/vert.x/security/advisories/GHSA-3g76-f9xq-8vp6 | Exploit Vendor Advisory |
| https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/381 | Exploit Issue Tracking Third Party Advisory |
| https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/381 | Exploit Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-05-06 10:16
Updated : 2026-06-17 11:01
NVD link : CVE-2026-6860
Mitre link : CVE-2026-6860
CVE.ORG link : CVE-2026-6860
JSON object : View
Products Affected
eclipse
- vert.x
