CVE Database
/

CVE-2026-6860

Back to search

CVE-2026-6860

Published: May 6, 2026

Modified: May 12, 2026

PUBLISHED

Description

A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com, any XYZ.example.com where xyz is a valid name can be used.

VendorProductVersions

Eclipse Foundation

Eclipse Vert.x

affected
4.3.4 - <= 4.5.26
affected
5.0.0 - <= 5.0.11

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now