Memory Consumption Issue in Reactor Netty HTTP Server
CVE-2026-47874

5.3MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
26 August 2026

What is CVE-2026-47874?

This vulnerability allows a malicious client to exploit the Reactor Netty HTTP server by sending HTTP/1.1 pipelined requests over a single connection. This results in excessive memory consumption, impacting server performance and availability. Affected versions include Reactor Netty 1.3.0 to 1.3.6, 1.1.0 to 1.2.18, and all versions prior to 1.0.52. It is crucial to address this issue to maintain optimal server functionality and prevent potential service disruption.

Affected Version(s)

Reactor Netty 1.3.0 <= 1.3.6

Reactor Netty 1.1.0 <= 1.2.18

Reactor Netty 0 <= 1.0.52

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.