Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-1023

22
FAUCET Score

CVE-2024-1023 describes a memory leak vulnerability in the Eclipse Vert.x toolkit, specifically impacting the Vert.x HTTP client when establishing connections to various hosts. This medium-severity vulnerability (CVSS 6.5) has a network attack vector with low complexity, allowing an authenticated attacker to cause a denial of service through memory exhaustion. While not actively exploited in the wild and lacking public exploit code or significant community discussion, the potential for accelerated exploitation exists if a server accepts arbitrary internet addresses.

Impacted Technologies

VendorProductVersion(s)CPE
Red HatRed Hat Build Of Keycloak
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Integration Camel Quarkus 2
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Build Of Apache Camel For Spring Boot 3
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Integration Camel K 1
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Data Grid 8
All Versions ImpactedCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.65%
Probability of exploitation in next 30 days
EPSS Percentile
74.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0165 is in the 87th percentile among its peer group of 21,977 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (22)

mavenpatch availablevia ghsa
Product: io.vertx:vertx-coreFixed in: 4.4.7
mavenpatch availablevia ghsa
Product: io.vertx:vertx-coreFixed in: 4.5.2
redhatpatch availablevia redhat_api
Product: Cryostat 2 on RHEL 8Fixed in: cryostat-tech-preview/cryostat-grafana-dashboard-rhel8:2.4.0-7
View patch
redhatpatch availablevia redhat_api
Product: Cryostat 2 on RHEL 8Fixed in: cryostat-tech-preview/cryostat-operator-bundle:2.4.0-4
View patch
redhatpatch availablevia redhat_api
Product: Cryostat 2 on RHEL 8Fixed in: cryostat-tech-preview/cryostat-reports-rhel8:2.4.0-4
View patch
redhatpatch availablevia redhat_api
Product: Cryostat 2 on RHEL 8Fixed in: cryostat-tech-preview/cryostat-rhel8:2.4.0-4
View patch
redhatpatch availablevia redhat_api
Product: Cryostat 2 on RHEL 8Fixed in: cryostat-tech-preview/cryostat-rhel8-operator:2.4.0-9
View patch
redhatpatch availablevia redhat_api
Product: Cryostat 2 on RHEL 8Fixed in: cryostat-tech-preview/jfr-datasource-rhel8:2.4.0-4
View patch
redhatpatch availablevia redhat_api
Product: MTA-6.2-RHEL-9Fixed in: mta/mta-windup-addon-rhel9:6.2.3-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Streams 2.7.0Fixed in: vert.x
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Quarkus 3.2.11.FinalFixed in: io.vertx/vertx-core:4.4.8.redhat-00001
View patch
redhatpatch availablevia redhat_api
Product: RHINT Service Registry 2.5.11 GAFixed in: vert.x
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Apache Camel 4.4.1 for Spring Boot 3.2Fixed in: vert.x
View patch
redhatpatch availablevia redhat_api
Product: CEQ 3.2Fixed in: vert.x
View patch
redhatno patchvia redhat_api
Product: Migration Toolkit for RuntimesFixed in: vert.x
redhatno patchvia redhat_api
Product: Red Hat Build of KeycloakFixed in: vert.x
redhatno patchvia redhat_api
Product: Red Hat Data Grid 8Fixed in: vert.x
redhatend of lifevia redhat_api
Product: Red Hat build of OptaPlanner 8Fixed in: vert.x
redhatend of lifevia redhat_api
Product: Red Hat JBoss Data Grid 7Fixed in: vert.x
redhatend of lifevia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: vert.x
redhatend of lifevia redhat_api
Product: Red Hat build of Apache Camel for Spring Boot 3Fixed in: vert.x
redhatend of lifevia redhat_api
Product: Red Hat Integration Camel Quarkus 2Fixed in: vert.x

Vendor Advisories (2)

mavenGHSA-5667-3wch-7q7wmedium

Eclipse Vert.x memory leak

Mar 27, 2024
redhatCVE-2024-1023Moderate

io.vertx/vertx-core: memory leak due to the use of Netty FastThreadLocal data structures in Vertx

Jan 26, 2024

References

access.redhat.com / errata/RHSA-2024:1662
access.redhat.com / errata/RHSA-2024:1706
access.redhat.com / errata/RHSA-2024:2088
access.redhat.com / errata/RHSA-2024:2833
access.redhat.com / errata/RHSA-2024:3527
access.redhat.com / errata/RHSA-2024:3989
access.redhat.com / errata/RHSA-2024:4884
access.redhat.com / security/cve/CVE-2024-1023
bugzilla.redhat.com / show_bug.cgi
github.com / eclipse-vertx/vert.x/issues/5078
github.com / eclipse-vertx/vert.x/pull/5080
github.com / eclipse-vertx/vert.x/pull/5082