CVE-2026-47844: Reactor Netty HTTP Server Leaks Exception Details
In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server must be configured with Brave Tracing. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using the Reactor Netty HTTP Server are affected only in the specific scenarios where the server is configured with Brave Tracing. The listed affected release ranges are 1.3.0 through 1.3.6, 1.1.0 through 1.2.18, and 1.0.52 and earlier.
What access does an attacker need to exploit it?
The severity vector indicates exploitation is network-accessible, has low attack complexity, and requires no privileges or user interaction. The impact is limited to integrity in the supplied vector; no confidentiality or availability impact is listed.
Are servers without Brave Tracing affected?
The leak requires the Reactor Netty HTTP Server to be configured with Brave Tracing. The provided information does not indicate that deployments without that configuration are affected.