Eclipse Vert.x 4.5.35 released!
We are extremely pleased to announce that Eclipse Vert.x version 4.5.35 has been released.
Since the release of Vert.x 4.5.34, quite a few bugs have been reported. We would like to thank you all for reporting these issues.
This release fixes the following vulnerabilities in Eclipse Vert.x.
- ChainAuthHandler bypasses scope checks on pre-authenticated users
- CRLF header injection in vertx-mail-client allows manipulation of outgoing SMTP messages
- Compressed WebSocket frames and messages maximum allocation is not enforced
- Heap exhaustion via unbounded RESP array allocation in Vert.x Redis client
- Denial of service via unbounded TDS message reassembly in Vert.x MSSQL client
- Unsafe Java deserialization of UDT column data in Vert.x DB2 client
- Denial of service via unbounded array allocation in Vert.x PostgreSQL client
- Denial of service via uncapped column count allocation in Vert.x MySQL client
- Denial of Service via Spoofed Message Length in Vert.x PostgreSQL Client
- Denial of Service via Unbounded Multi-Packet Reassembly in Vert.x MySQL Client
- Quadratic complexity in JSON Schema uniqueItems validation
- Eclipse Vert.x MQTT client unbounded inbound QoS 2 message retention allows broker-driven denial of service
- gRPC compressed messages are only bounded by their compressed size, allowing compression bomb attacks
In addition, this release ships with Netty 4.1.139.Final that fixes a few vulnerabilities, details can be found in the Netty release page.
The 4.5.35 release notes can be found on the wiki.
You can bootstrap a Vert.x 4 project using start.vertx.io.
The release artifacts have been deployed to Maven Central.
The Vert.x 4 eventbus JavaScript client library is now available in a single location and it now usable standalone or it can easily be integrated with any frontend build tool.
The Vert.x distribution is available from SDKMan and our HomeBrew TAP.
Vert.x follows a 2 years policy after a major release, as consequence Vert.x remains supported until April 2027 and get bug fixes, you should consider upgrading your application to Vert.x 5.
That’s it! Happy coding and see you soon on our user or dev channels.


