Input validation error in Reactor Netty - CVE-2026-47845
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to affect the integrity of IP-based access control decisions.
The vulnerability exists due to improper input validation in Reactor Netty HTTP Server HAProxy Protocol address handling when processing proxied connections. A remote attacker can send a specially crafted proxied connection to affect the integrity of IP-based access control decisions.
The issue occurs only when the application is configured to use HAProxy Protocol.