Eclipse Vert.x 5.1.10 released!
We are extremely pleased to announce that Eclipse Vert.x version 5.1.10 has been released.
Since the release of Vert.x 5.1.8, quite a few bugs have been reported. We would like to thank you all for reporting these issues.
The version 5.1.9 does exist but should not be used due to and error during the release process.
This release fixes the following vulnerabilities in Eclipse Vert.x.
- Incomplete SSL context cache key, leading to client SSL context property mismatch
- ChainAuthHandler bypasses scope checks on pre-authenticated users
- Vert.x HTTP/1.x decoder does not correctly handle canonicalized headers leading to request smuggling
- CRLF header injection in vertx-mail-client allows manipulation of outgoing SMTP messages
- Compressed WebSocket frames and messages maximum allocation is not enforced
- HTTP Proxy body transformer interceptor does not correctly ensure the max buffered byte check
- Heap exhaustion via unbounded RESP array allocation in Vert.x Redis client
- Denial of service via unbounded TDS message reassembly in Vert.x MSSQL client
- Unsafe Java deserialization of UDT column data in Vert.x DB2 client
- Denial of service via unbounded array allocation in Vert.x PostgreSQL client
- Denial of service via uncapped column count allocation in Vert.x MySQL client
- Denial of Service via Spoofed Message Length in Vert.x PostgreSQL Client
- Denial of Service via Unbounded Multi-Packet Reassembly in Vert.x MySQL Client
- Quadratic complexity in JSON Schema uniqueItems validation
- Eclipse Vert.x MQTT client unbounded inbound QoS 2 message retention allows broker-driven denial of service
- gRPC compressed messages are only bounded by their compressed size, allowing compression bomb attacks
In addition, this release ships with Netty 4.2.19.Final that fixes a few vulnerabilities, details can be found in the Netty release page.
The 5.1.10 release notes can be found on the wiki.
You can bootstrap a Vert.x 5 project using start.vertx.io.
The release artifacts have been deployed to Maven Central.
The Vert.x eventbus JavaScript client library is now available in a single location and it now usable standalone or it can easily be integrated with any frontend build tool.
That’s it! Happy coding and see you soon on our user or dev channels.




