---
id: CVE-2025-11965
title: >-
  In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler
  configuration for restricting access to hidden files fails to restrict access
  to hidden directories, allowing unauthorized users to retrieve files within
  them…
summary: >-
  In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler
  configuration for restricting access to hidden files fails to restrict access
  to hidden directories, allowing unauthorized users to retrieve files within
  them…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-552
vendor: eclipse
product: vert.x
affected:
  - 'vert.x >= 4.0.0, < 4.5.22'
  - 'vert.x >= 5.0.0, < 5.0.5'
patched:
  - vert.x 5.0.5
published: '2025-10-22'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11965'
references:
  - url: 'https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/304'
    label: emo@eclipse.org
tags:
  - nvd
epss: 0.00503
epssPercentile: 0.41074
ingestedAt: '2026-10-08T11:31:27.492Z'
---

## Overview

In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to hidden files fails to restrict access to hidden directories, allowing unauthorized users to retrieve files within them (e.g. '.git/config').

## Affected

- `vert.x >= 4.0.0, < 4.5.22`
- `vert.x >= 5.0.0, < 5.0.5`

## Remediation

Upgrade past the affected range:

- `vert.x 5.0.5`
