SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47848

MEDIUM · CVSS 6.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Reactor Netty WebSocket client is vulnerable to credential leakage during WebSocket handshake redirects when the HTTP client is configured to follow redirects. This issue affects versions 1.3.0 to 1.3.6, 1.1.0 to 1.2.18, and 1.0.52 and earlier. Organizations utilizing these versions should prioritize patching to mitigate potential exposure of sensitive information.

CVE
CVE-2026-47848
Severity
MEDIUM
CVSS
6.1
EPSS
0.16%

Original NVD Description

In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)