VMwareCVE-2026-47844
In specific scenarios
Medium5.3CVE-2026-47844 · Published Aug 26, 2026 · updated Sep 4, 2026
In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server must be configured with Brave Tracing. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Reactor Netty Product | >= 1.3.0, <= 1.3.6 | No fix yet |
| >= 1.1.0, <= 1.2.18 | No fix yet | |
| <= 1.0.52 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
More VMware advisories
All VMware| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 26 | VMware Reactor Netty: open redirect | Medium6.1 | No fix yet |
| Aug 26 | In specific scenarios involving multiple clients with different DNS resolver... | Low3.7 | No fix yet |
| Aug 26 | VMware Spring Security: weak encryption | Medium6.5 | No fix yet |
| Aug 26 | Spring Data JPA's Sort validation can be bypassed | Medium4.8 | No fix yet |
| Aug 26 | VMware Spring Cloud Config: race condition | High7.2 | No fix yet |
| Aug 26 | VMware Spring Cloud Config: missing authentication | Medium6.8 | No fix yet |