CVE-2026-47863
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7.19 and earlier
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Reactor Core | 3.8.0 <= 3.8.6 | affected |
| Spring | Reactor Core | 0 <= 3.7.19 | affected |
Weaknesses
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.