Credential Leakage in Reactor Netty HTTP Client
CVE-2026-41715
6.1MEDIUM
What is CVE-2026-41715?
A security issue has been identified in the Reactor Netty HTTP client, where in certain cases of HTTP redirects from secure to insecure endpoints, sensitive credentials may be unintentionally exposed. This vulnerability arises specifically when the HTTP client is configured to follow redirects, thus leading to potential leakage of user credentials if improperly managed. It is crucial for users of the affected versions to take immediate action to mitigate this risk.
Affected Version(s)
Reactor Netty 1.0.0 < 1.0.52
Reactor Netty 1.1.0 < 1.1.36
Reactor Netty 1.2.0 < 1.2.17.1
