VYPR

Reactor Netty

by Reactor Netty

CVEs (3)

  • CVE-2026-47848MedAug 26, 2026
    risk 0.40cvss 6.1epss 0.00

    In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Reactor Netty 1.3.0 - 1.3.6…

  • CVE-2026-47874MedAug 27, 2026
    risk 0.34cvss 5.3epss 0.00

    The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

  • CVE-2026-47843LowAug 26, 2026
    risk 0.24cvss 3.7epss 0.00

    In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configured DNS resolver. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier