{"id":"CVE-2025-11965","title":"In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to hidden files fails to restrict access to hidden directories, allowing unauthorized users to retrieve files within them…","summary":"In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to hidden files fails to restrict access to hidden directories, allowing unauthorized users to retrieve files within them…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-552"],"vendor":"eclipse","product":"vert.x","affected":["vert.x >= 4.0.0, < 4.5.22","vert.x >= 5.0.0, < 5.0.5"],"patched":["vert.x 5.0.5"],"published":"2025-10-22","updated":"2026-10-08","sourceUpdated":"2026-10-08T11:10:00.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-11965","references":[{"url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/304","label":"emo@eclipse.org"}],"tags":["nvd"],"epss":0.00503,"epssPercentile":0.41074,"ingestedAt":"2026-10-08T11:31:27.492Z","slug":"CVE-2025-11965","body":"## Overview\n\nIn Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to hidden files fails to restrict access to hidden directories, allowing unauthorized users to retrieve files within them (e.g. '.git/config').\n\n## Affected\n\n- `vert.x >= 4.0.0, < 4.5.22`\n- `vert.x >= 5.0.0, < 5.0.5`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `vert.x 5.0.5`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}