CVE-2026-47863
In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7.19 and earlier
- Published Aug 27, 2026
- CVSS 7.5 high
- 0.4% chance of exploitation in the next 30 days (EPSS)