Information disclosure in Reactor Netty - CVE-2026-47844
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify application behavior by causing exception details to be leaked across unrelated requests.
The vulnerability exists due to improper isolation of exception details in the Reactor Netty HTTP Server when handling requests. A remote attacker can send a request that triggers an exception to modify application behavior by causing exception details to be leaked across unrelated requests.
Only servers configured with Brave Tracing are vulnerable.