Disclosure summary
In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into generated HTML without proper escaping in the href, title, and link attributes. An attacker who can create or rename files or directories within a served path can craft filenames containing malicious script or HTML content, leading to stored cross-site scripting (XSS) that executes in the context of users viewing the affected directory listing.
Source-reported weakness categories
CWE-79, CWE-80
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2025-11966
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| eclipse | vert.x | * {"versionStartIncluding":"5.0.0","versionEndExcluding":"5.0.5"} |
Original records & references
- NIST NVD record
- CVE Program record
- gitlab.eclipse.org — Exploit, Issue Tracking, Vendor Advisory
PUBLISHED 2025-10-22T11:15:31-04:00
MODIFIED 2026-10-08T07:10:00-04:00
INGESTED 2026-10-08T12:35:06-04:00