Inconsistent interpretation of HTTP requests in Vert.x - CVE-2026-1002

 

Inconsistent interpretation of HTTP requests in Vert.x - CVE-2026-1002

Published: August 18, 2026


Vulnerability identifier: #VU144038
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-1002
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.

The vulnerability exists due to improper implementation of the C. rule of section 5.2.4 of RFC3986. A remote attacker can manipulate Vert.x Web static handler component cache to deny access to static files served by the handler using specifically crafted request URI.


Affected software

Vert.x
IBM Automation Decision Services
Red Hat Integration Camel Extensions for Quarkus
Red Hat Camel for Spring Boot

How to mitigate CVE-2026-1002

Install updates from vendor's website.

Vert.x - addressed in versions 4.5.24, 5.0.7
IBM Automation Decision Services - addressed in versions 24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4
Red Hat Integration Camel Extensions for Quarkus - update to p
Red Hat Camel for Spring Boot - addressed in versions 4.14, 4.14.4

External References

Related Security Bulletins