CVE-2026-47845: Reactor Netty HTTP Server may incorrectly evaluate proxy addresses
In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Reactor Nettyto a version that resolves this vulnerability.Fixed in 1.0.52 - Upgrade
Upgrade
Reactor Nettyto a version that resolves this vulnerability.Fixed in 1.1.0 - Upgrade
Upgrade
Reactor Nettyto a version that resolves this vulnerability.Fixed in 1.2.18 - Upgrade
Upgrade
Reactor Nettyto a version that resolves this vulnerability.Fixed in 1.3.0 - Upgrade
Upgrade
Reactor Nettyto a version that resolves this vulnerability.Fixed in 1.3.6
Event History
Frequently Asked Questions
Is a default Reactor Netty HTTP Server deployment affected?
The issue requires the application to be configured to use HAProxy Protocol. Deployments that do not enable HAProxy Protocol are not described as affected.
Which Reactor Netty versions are affected?
Affected ranges are Reactor Netty 1.3.0 through 1.3.6, 1.1.0 through 1.2.18, and 1.0.52 and earlier.
What security impact can result from exploitation?
The reported impact is integrity-related: an attacker may cause the server to incorrectly evaluate the remote IP address. The provided severity vector indicates network exploitation with no privileges or user interaction required, and no reported confidentiality or availability impact.