SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47844

MEDIUM · CVSS 5.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Reactor Netty HTTP Server is vulnerable to information leakage, where exception details can be inadvertently exposed across unrelated requests when configured with Brave Tracing. This could potentially allow attackers to gather sensitive information about the server's operations. Organizations using affected versions of Reactor Netty should prioritize patching to mitigate the risk of data exposure.

CVE
CVE-2026-47844
Severity
MEDIUM
CVSS
5.3
EPSS
0.15%

Original NVD Description

In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server must be configured with Brave Tracing. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)