In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.
Reactor Netty 1.3.0 - 1.3.6
Reactor Netty 1.1.0 - 1.2.18
Reactor Netty 1.0.52 and earlier
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-47848 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-26 20:17
Updated : 2026-09-04 19:09
NVD link : CVE-2026-47848
Mitre link : CVE-2026-47848
CVE.ORG link : CVE-2026-47848
JSON object : View
Products Affected
broadcom
- reactor_netty
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
