Information disclosure in Reactor Netty - CVE-2026-47844

 

Information disclosure in Reactor Netty - CVE-2026-47844

Published: August 28, 2026


Vulnerability identifier: #VU146288
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47844
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify application behavior by causing exception details to be leaked across unrelated requests.

The vulnerability exists due to improper isolation of exception details in the Reactor Netty HTTP Server when handling requests. A remote attacker can send a request that triggers an exception to modify application behavior by causing exception details to be leaked across unrelated requests.

Only servers configured with Brave Tracing are vulnerable.


Affected software

Reactor Netty

How to mitigate CVE-2026-47844

Install security update from vendor's website.

Reactor Netty - addressed in versions 1.0.53, 1.2.19, 1.3.6.1, 1.3.7

External References

Related Security Bulletins