CVE-2026-47874
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Summary
The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Reactor Netty | 1.3.0 <= 1.3.6 | affected |
| Spring | Reactor Netty | 1.1.0 <= 1.2.18 | affected |
| Spring | Reactor Netty | 0 <= 1.0.52 | affected |
Weaknesses
- CWE-770 Allocation of Resources Without Limits or Throttling
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.