Improper control of a resource through its lifetime in Reactor Netty - CVE-2026-47843

 

Improper control of a resource through its lifetime in Reactor Netty - CVE-2026-47843

Published: August 28, 2026


Vulnerability identifier: #VU146287
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47843
CWE-ID: CWE-664
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to route traffic to unintended destinations.

The vulnerability exists due to improper resource management in DNS resolver handling when dynamically creating multiple clients with different custom DNS resolver configurations. A remote attacker can trigger reuse of a previously configured DNS resolver to route traffic to unintended destinations.

The issue occurs in specific scenarios involving multiple clients such as HttpClient or TcpClient that rely on different custom configuration.


Affected software

Reactor Netty

How to mitigate CVE-2026-47843

Install security update from vendor's website.

Reactor Netty - addressed in versions 1.0.53, 1.2.19, 1.3.6.1, 1.3.7

External References

Related Security Bulletins