CVE-2026-47857

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and earlier

  • Published Aug 27, 2026
  • CVSS 5.9 medium
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-47857 at the National Vulnerability Database