Credential Leak Vulnerability in Reactor Netty HTTP Client by Pivotal Software
CVE-2025-22227

6.1MEDIUM

Key Information:

Vendor

Vmware

Vendor
CVE Published:
16 July 2025

What is CVE-2025-22227?

The Reactor Netty HTTP client may inadvertently expose authentication credentials during chained redirect scenarios. This issue arises when the client is explicitly set to follow redirects, which can lead to sensitive information being leaked to unintended recipients. Proper configuration and an understanding of the redirect handling process are essential to mitigate the risks associated with this vulnerability.

Affected Version(s)

Reactor Netty 1.0.x < 1.0.49 (Reactor BOM 2020.0.48)

Reactor Netty 1.1.x < 1.1.32 (Reactor BOM 2022.0.27 and 2023.0.20)

Reactor Netty 1.2.x < 1.2.8 (Reactor BOM 2024.0.8)

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-22227 : Credential Leak Vulnerability in Reactor Netty HTTP Client by Pivotal Software