Information disclosure in Reactor Netty - CVE-2026-47848

 

Information disclosure in Reactor Netty - CVE-2026-47848

Published: August 28, 2026


Vulnerability identifier: #VU146290
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47848
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper handling of credential forwarding in the Reactor Netty WebSocket client when processing WebSocket handshake redirects to a different origin. A remote attacker can trigger a crafted redirect during the WebSocket handshake to disclose sensitive information.

The HTTP client must be explicitly configured to follow redirects, and user interaction is required.


Affected software

Reactor Netty

How to mitigate CVE-2026-47848

Install security update from vendor's website.

Reactor Netty - addressed in versions 1.0.53, 1.2.19, 1.3.6.1, 1.3.7

External References

Related Security Bulletins