Vert.x has a DoS via unbounded server-side SNI SslContext cache growth
Potential unbounded server-side SNI SslContext cache growth in Vert.x TLS handling, with = resource-exhaustion / DoS impact. On affected versions, matching server-side SNI names are cached via computeIfAbsent(serverName, …) in a serverName-keyed SslContext cache. The implementation differs slightly by branch, but the same sink appears to be present in released versions 4.3.4 through 5.0.11: 4.3.x: SSLHelper 4.4.x / 4.5.x: SslChannelProvider 5.0.x and current master: SslContextProvider When server-side SNI is enabled …