CVE-2026-47863

Summary

In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7.19 and earlier

Affected Software

VendorProductVersion RangeStatus
SpringReactor Core3.8.0 <= 3.8.6affected
SpringReactor Core0 <= 3.7.19affected

Weaknesses

  • CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

References