CVE-2026-47857
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and earlier
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Reactor Core | 3.8.0 <= 3.8.6 | affected |
| Spring | Reactor Core | 3.5.0 <= 3.7.19 | affected |
| Spring | Reactor Core | 0 <= 3.4.41 | affected |
Weaknesses
- CWE-190 Integer Overflow or Wraparound
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.