CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty...Show more |
2Broadcom Pivotal2Reactor Netty Reactor NettySep 4, 2026 Nov 28, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition....Show more |
2Broadcom Pivotal2Reactor Netty Reactor NettySep 4, 2026 Nov 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifica...Show more |
2Broadcom Pivotal2Reactor Netty Reactor NettySep 4, 2026 Oct 19, 2022 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affe...Show more |
2Broadcom Pivotal2Reactor Netty Reactor NettySep 4, 2026 Mar 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be closed prematurely instead of producing a 400 response. |
2Broadcom Pivotal2Reactor Netty Reactor NettySep 4, 2026 Mar 3, 2020 N/A· v4 5.9 MEDIUM· v3 4.9 MEDIUM· v2 The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to h...Show more |
2Broadcom Pivotal2Reactor Netty Reactor NettySep 4, 2026 Oct 17, 2019 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they hav...Show more |