CVE-2026-15076: CWE-346: Origin Validation Error in Eclipse Foundation Eclipse Vert.x
In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not validate that the Domain attribute of a Set-Cookie response header matches the originating server's domain, in violation of RFC 6265 section 5.3. An attacker who controls any server that the victim application contacts can inject a cookie scoped to an arbitrary third-party domain; because the session store performs no cross-domain ownership check, it stores and later transmits that cookie to the targeted domain. When the victim application subsequently sends a request to the targeted domain using the same WebClientSession, it presents the attacker-injected cookie, causing the receiving service to process the request under the attacker's account. Sensitive data included in the victim application's requests, such as payment amounts, card details, or other API payloads, may then be accessible to the attacker through their own account on that service.
AI Analysis
Technical Summary
CVE-2026-15076 describes an origin validation error (CWE-346) in Eclipse Vert.x Web Client's WebClientSession component. The vulnerability arises because the component does not verify that the Domain attribute in Set-Cookie headers matches the domain of the server that sent the response, violating RFC 6265 section 5.3. An attacker controlling any server contacted by the victim can inject cookies scoped to arbitrary third-party domains. Since the session store does not perform cross-domain ownership checks, it stores and later sends these attacker-injected cookies to the targeted domains. This can cause the targeted service to process requests under the attacker's account, potentially exposing sensitive information such as payment details or API payloads.
Potential Impact
An attacker who controls any server contacted by the victim application can inject cookies scoped to arbitrary third-party domains. When the victim subsequently sends requests to those domains using the same WebClientSession, the attacker-injected cookies are presented, causing the targeted service to treat the requests as coming from the attacker’s account. This can lead to unauthorized access to sensitive data included in the victim's requests, such as payment information or API payloads.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is currently documented. Until a patch is available, avoid using vulnerable versions of Eclipse Vert.x Web Client in contexts where untrusted servers are contacted or isolate WebClientSession usage to trusted domains only.
CVE-2026-15076: CWE-346: Origin Validation Error in Eclipse Foundation Eclipse Vert.x
Description
In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not validate that the Domain attribute of a Set-Cookie response header matches the originating server's domain, in violation of RFC 6265 section 5.3. An attacker who controls any server that the victim application contacts can inject a cookie scoped to an arbitrary third-party domain; because the session store performs no cross-domain ownership check, it stores and later transmits that cookie to the targeted domain. When the victim application subsequently sends a request to the targeted domain using the same WebClientSession, it presents the attacker-injected cookie, causing the receiving service to process the request under the attacker's account. Sensitive data included in the victim application's requests, such as payment amounts, card details, or other API payloads, may then be accessible to the attacker through their own account on that service.
CVSS v4.0
Score 8.2high
Affected software
pkg:github/Eclipse Vert.xRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-15076 describes an origin validation error (CWE-346) in Eclipse Vert.x Web Client's WebClientSession component. The vulnerability arises because the component does not verify that the Domain attribute in Set-Cookie headers matches the domain of the server that sent the response, violating RFC 6265 section 5.3. An attacker controlling any server contacted by the victim can inject cookies scoped to arbitrary third-party domains. Since the session store does not perform cross-domain ownership checks, it stores and later sends these attacker-injected cookies to the targeted domains. This can cause the targeted service to process requests under the attacker's account, potentially exposing sensitive information such as payment details or API payloads.
Potential Impact
An attacker who controls any server contacted by the victim application can inject cookies scoped to arbitrary third-party domains. When the victim subsequently sends requests to those domains using the same WebClientSession, the attacker-injected cookies are presented, causing the targeted service to treat the requests as coming from the attacker’s account. This can lead to unauthorized access to sensitive data included in the victim's requests, such as payment information or API payloads.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is currently documented. Until a patch is available, avoid using vulnerable versions of Eclipse Vert.x Web Client in contexts where untrusted servers are contacted or isolate WebClientSession usage to trusted domains only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- eclipse
- Date Reserved
- 2026-07-08T15:26:03.652Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a55f44d68715ace431bbf33
Added to database: 07/14/2026, 08:33:17 UTC
Last enriched: 07/14/2026, 08:47:43 UTC
Last updated: 08/28/2026, 10:52:06 UTC
Views: 112
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.