← Back

CVE-2025-22227

nvd nist
Published: Jul 16, 2025Modified: Jun 17, 2026Deferred

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: security@vmware.com (Secondary)

Description

In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.

References (1)

Timeline

No history available yet.