CVE-2026-47857

Summary

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and earlier

Affected Software

VendorProductVersion RangeStatus
SpringReactor Core3.8.0 <= 3.8.6affected
SpringReactor Core3.5.0 <= 3.7.19affected
SpringReactor Core0 <= 3.4.41affected

Weaknesses

  • CWE-190 Integer Overflow or Wraparound

References