Improper DNS Resolver Configuration in Reactor Netty by Pivotal
CVE-2026-47843

3.7LOW

Key Information:

Vendor

Spring

Vendor
CVE Published:
26 August 2026

What is CVE-2026-47843?

In specified conditions involving multiple clients employing different DNS resolver setups, Reactor Netty is prone to erroneously reusing a DNS resolver that was previously configured. This flaw could lead to inconsistent network behavior or exposure to DNS-related vulnerabilities, potentially compromising the integrity of the data being transmitted across the network.

Affected Version(s)

Reactor Netty 1.3.0 <= 1.3.6

Reactor Netty 1.1.0 <= 1.2.18

Reactor Netty 0 <= 1.0.52

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.