Broadcom Reactor Netty — known CVE vulnerabilities
Every CVE whose affected-product data names Broadcom Reactor Netty, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (10)
CVE-2019-11284 — CVSS 8.6 (high): Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated…
CVE-2020-5403 — CVSS 7.5 (high): Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be closed prematurely…
CVE-2023-34062 — CVSS 7.5 (high): In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using…
CVE-2026-47848 — CVSS 6.1 (medium): In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak…
CVE-2020-5404 — CVSS 5.9 (medium): The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a…
CVE-2023-34054 — CVSS 5.3 (medium): In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide…
CVE-2026-47844 — CVSS 5.3 (medium): In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the…
CVE-2026-47845 — CVSS 5.3 (medium): In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order…
CVE-2022-31684 — CVSS 4.3 (medium): Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers…
CVE-2026-47843 — CVSS 3.7 (low): In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a…