Skip to content
VMwareCVE-2026-47844

In specific scenarios

Medium5.3CVE-2026-47844 · Published Aug 26, 2026 · updated Sep 4, 2026

In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server must be configured with Brave Tracing. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

VMware advisory

Affected versions

PackageAffectedFixed in
Reactor Netty
Product
>= 1.3.0, <= 1.3.6No fix yet
>= 1.1.0, <= 1.2.18No fix yet
<= 1.0.52No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)

More VMware advisories

All VMware
Advisory
VMware Reactor Netty: open redirect
Medium6.1Aug 26
In specific scenarios involving multiple clients with different DNS resolver...
Low3.7Aug 26
VMware Spring Security: weak encryption
Medium6.5Aug 26
Spring Data JPA's Sort validation can be bypassed
Medium4.8Aug 26
VMware Spring Cloud Config: race condition
High7.2Aug 26
VMware Spring Cloud Config: missing authentication
Medium6.8Aug 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.