VendorsBroadcomreactor_nettyall versions
Vulnerabilities

Broadcom Reactor Netty

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2019-11284
Reactor Netty authentication leak in redirects
Published 2019-10-17 · Modified
8.6EPSS 0.009
CVE-2020-5403
DoS Via Malformed URL with Reactor Netty HTTP Server
Published 2020-03-03 · Modified
7.5EPSS 0.011
CVE-2023-34062
In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifically, an application is vulnerable if Reactor Netty HTTP Server is configured to serve static resources.
Published 2023-11-15 · Modified
7.5EPSS 0.011
CVE-2023-34054
Reactor Netty HTTP Server Metrics DoS Vulnerability
Published 2023-11-28 · Modified
7.5EPSS 0.009
CVE-2020-5404
Authentication Leak On Redirect With Reactor Netty HttpClient
Published 2020-03-03 · Modified
6.5EPSS 0.007
CVE-2026-47848
Reactor Netty WebSocket Client Leaks Credentials On Redirect
Published 2026-08-26 · Analyzed
6.1EPSS 0.002
CVE-2026-47845
Reactor Netty HTTP Server may incorrectly evaluate proxy addresses
Published 2026-08-26 · Analyzed
5.3EPSS 0.002
CVE-2026-47844
Reactor Netty HTTP Server Leaks Exception Details
Published 2026-08-26 · Analyzed
5.3EPSS 0.001
CVE-2022-31684
Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled.
Published 2022-10-19 · Modified
4.3EPSS 0.006
CVE-2026-47843
Reactor Netty may incorrectly route traffic due to DNS resolver reuse
Published 2026-08-26 · Analyzed
3.7EPSS 0.002