Information disclosure in Reactor Netty - CVE-2026-47848
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper handling of credential forwarding in the Reactor Netty WebSocket client when processing WebSocket handshake redirects to a different origin. A remote attacker can trigger a crafted redirect during the WebSocket handshake to disclose sensitive information.
The HTTP client must be explicitly configured to follow redirects, and user interaction is required.