Vert.x has a DoS via unbounded server-side SNI SslContext cache growth
Moderate severity
GitHub Reviewed
Published
May 6, 2026
in
eclipse-vertx/vert.x
•
Updated Jun 2, 2026
Package
Affected versions
>= 4.3.4, <= 4.3.8
>= 4.4.0, <= 4.4.9
>= 4.5.0, <= 4.5.26
>= 5.0.0, <= 5.0.11
Patched versions
4.5.27
5.0.12
Description
Published by the National Vulnerability Database
May 6, 2026
Published to the GitHub Advisory Database
May 9, 2026
Reviewed
May 9, 2026
Last updated
Jun 2, 2026
Potential unbounded server-side SNI
SslContextcache growth in Vert.x TLS handling, with = resource-exhaustion / DoS impact. On affected versions, matching server-side SNI names are cached viacomputeIfAbsent(serverName, ...)in a serverName-keyedSslContextcache.The implementation differs slightly by branch, but the same sink appears to be present in released versions
4.3.4through5.0.11:4.3.x:SSLHelper4.4.x/4.5.x:SslChannelProvider5.0.xand currentmaster:SslContextProviderWhen server-side SNI is enabled and wildcard or otherwise broad hostname mappings are used, an unauthenticated client can send many distinct matching SNI names and cause the server to retain increasing numbers of
SslContextentries over time, leading to increasing memory consumption and possible DoS conditions.Steps to reproduce
setSsl(true)andsetSni(true).What are the affected versions?
Affected released versions confirmed on
origin:4.3.4through4.3.84.4.0through4.4.94.5.0through4.5.265.0.0through5.0.11Not affected by the same sink:
4.0.xthrough4.2.x4.3.0through4.3.3References