Loading HuntDB...

GHSA-45xm-v8gq-7jqx

GitHub Security Advisory

Excessive memory allocation

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a reasonnable limit (8192 bytes) above which the WebSocket gets an HTTP response with the 413 status code and the connection gets closed.

Affected Packages

Maven io.vertx:vertx-core
Affected versions: 3.0.0 (fixed in 3.5.4)

Related CVEs

Key Information

GHSA ID
GHSA-45xm-v8gq-7jqx
Published
October 17, 2018 4:19 PM
Last Modified
April 25, 2022 8:23 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
io.vertx:vertx-core
GitHub Reviewed
✓ Yes

Dataset

Last updated: November 26, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.