VYPR

Reactor Netty

by Spring Projects

Source repositories

CVEs (2)

  • CVE-2026-41715MedJun 9, 2026
    risk 0.33cvss 6.1epss 0.00

    In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Affected versions: Reactor Netty…

  • CVE-2023-34054MedNov 28, 2023
    risk 0.28cvss 5.3epss 0.01

    In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable if Reactor Netty…