Spring Reactor Netty

5 known vulnerabilities in Spring Reactor Netty, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-47874 CVSS 5.3 medium The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server…
  • CVE-2026-47845 CVSS 5.3 medium In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order…
  • CVE-2026-47848 CVSS 6.1 medium In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak…
  • CVE-2026-47844 CVSS 3.7 low In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen…
  • CVE-2026-47843 CVSS 3.7 low In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a…