← Back

CVE-2026-47874

nvd nist
Published: Aug 27, 2026Modified: Sep 2, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: security@vmware.com (Secondary)

Description

The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

Affected (3)

1 product
Reactor Netty
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Pivotal
Before 1.0.53
From 1.1.0 to 1.2.19
From 1.3.0 to 1.3.6.1

References (1)

Source: security@vmware.com
Vendor Advisory

Timeline

No history available yet.