Information disclosure in Reactor Netty - CVE-2026-41715
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose credentials.
The vulnerability exists due to improper handling of credential forwarding in the Reactor Netty HTTP client redirect handling when following redirects from a secure endpoint to an insecure endpoint. A remote attacker can trigger a protocol downgrade redirect to disclose credentials.
The HTTP client must be explicitly configured to follow redirects, and user interaction is required.