---
id: CVE-2025-11966
title: >-
  In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory
  listing" is enabled, file and directory names are inserted into generated HTML
  without proper escaping in the href, title, and link attributes
summary: >-
  In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory
  listing" is enabled, file and directory names are inserted into generated HTML
  without proper escaping in the href, title, and link attributes. An attacker
  wh…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
  - CWE-80
vendor: eclipse
product: vert.x
affected:
  - 'vert.x >= 4.0.0, < 4.5.22'
  - 'vert.x >= 5.0.0, < 5.0.5'
patched:
  - vert.x 5.0.5
published: '2025-10-22'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11966'
references:
  - url: 'https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/303'
    label: emo@eclipse.org
tags:
  - nvd
epss: 0.00291
epssPercentile: 0.19878
ingestedAt: '2026-10-08T11:31:27.492Z'
---

## Overview

In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into generated HTML without proper escaping in the href, title, and link attributes. An attacker who can create or rename files or directories within a served path can craft filenames containing malicious script or HTML content, leading to stored cross-site scripting (XSS) that executes in the context of users viewing the affected directory listing.

## Affected

- `vert.x >= 4.0.0, < 4.5.22`
- `vert.x >= 5.0.0, < 5.0.5`

## Remediation

Upgrade past the affected range:

- `vert.x 5.0.5`
