The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory.
Reactor Netty 1.3.0 - 1.3.6
Reactor Netty 1.1.0 - 1.2.18
Reactor Netty 1.0.52 and earlier
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-47874 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-27 01:17
Updated : 2026-09-02 15:50
NVD link : CVE-2026-47874
Mitre link : CVE-2026-47874
CVE.ORG link : CVE-2026-47874
JSON object : View
Products Affected
pivotal
- reactor_netty
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
