CVE-2026-47844

Summary

In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server must be configured with Brave Tracing. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

Affected Software

VendorProductVersion RangeStatus
SpringReactor Netty1.3.0 <= 1.3.6affected
SpringReactor Netty1.1.0 <= 1.2.18affected
SpringReactor Netty0 <= 1.0.52affected

Weaknesses

  • CWE-668 Exposure of Resource to Wrong Sphere

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References