{"id":"CVE-2018-12544","details":"In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a provided schema.","aliases":["GHSA-qh3m-qw6v-qvhg"],"modified":"2026-07-08T17:56:14.121121Z","published":"2018-10-10T20:29:00.710Z","references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2946"},{"type":"FIX","url":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=539568"},{"type":"FIX","url":"https://github.com/vert-x3/vertx-web/issues/1021"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eclipse-vertx/vert.x","events":[{"introduced":"9460cabbf623945495e6108c9d1979a9e7b5d8e7"},{"last_affected":"4c5ea4d082ab02093ba9eb85fcde47a37059eb5d"}],"database_specific":{"cpe":["cpe:2.3:a:eclipse:vert.x:3.5.0:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.0:beta1:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.2:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.2:cr1:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.2:cr2:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.2:cr3:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.3:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.3:cr1:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.5.0"},{"last_affected":"3.5.0"},{"introduced":"3.5.0-beta1"},{"last_affected":"3.5.0-beta1"},{"introduced":"3.5.1"},{"last_affected":"3.5.1"},{"introduced":"3.5.2"},{"last_affected":"3.5.2"},{"introduced":"3.5.2-cr1"},{"last_affected":"3.5.2-cr1"},{"introduced":"3.5.2-cr2"},{"last_affected":"3.5.2-cr2"},{"introduced":"3.5.2-cr3"},{"last_affected":"3.5.2-cr3"},{"introduced":"3.5.3"},{"last_affected":"3.5.3"},{"introduced":"3.5.3-cr1"},{"last_affected":"3.5.3-cr1"}],"source":"CPE_STRING"}}],"versions":["3.5.0","3.5.0-beta1","3.5.1","3.5.2","3.5.2-cr1","3.5.2-cr2","3.5.2-cr3","3.5.3","3.5.3-cr1","3.5.3.CR1","3.5.2.CR3","3.5.2.CR2","3.5.2.CR1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-12544.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/vert-x3/vertx-web","events":[{"introduced":"7b5225584ff119886b13017ace74bb90e780edb6"},{"last_affected":"3fe3873cc28b4d833c90f8989ff797a7b463da2c"}],"database_specific":{"cpe":["cpe:2.3:a:eclipse:vert.x:3.5.0:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.0:beta1:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.2:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.2:cr1:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.2:cr2:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.2:cr3:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.3:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:vert.x:3.5.3:cr1:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.5.0"},{"last_affected":"3.5.0"},{"introduced":"3.5.0-beta1"},{"last_affected":"3.5.0-beta1"},{"introduced":"3.5.1"},{"last_affected":"3.5.1"},{"introduced":"3.5.2"},{"last_affected":"3.5.2"},{"introduced":"3.5.2-cr1"},{"last_affected":"3.5.2-cr1"},{"introduced":"3.5.2-cr2"},{"last_affected":"3.5.2-cr2"},{"introduced":"3.5.2-cr3"},{"last_affected":"3.5.2-cr3"},{"introduced":"3.5.3"},{"last_affected":"3.5.3"},{"introduced":"3.5.3-cr1"},{"last_affected":"3.5.3-cr1"}],"source":"CPE_STRING"}}],"versions":["3.5.0","3.5.0-beta1","3.5.1","3.5.2","3.5.2-cr1","3.5.2-cr2","3.5.2-cr3","3.5.3","3.5.3-cr1","3.5.3.CR1","3.5.2.CR3","3.5.2.CR2","3.5.2.CR1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-12544.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}