Description
The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier
CVSS 5.3EPSS 0.23800000000000002%Risk 0.54
View source- Published
- 2026-08-27 01:17:33
- Affected versions
- <=1.3.6, <=1.2.18, <=1.0.52
- Type
- Library
- Last modified
- 2026-08-27 17:18:33
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L