CVE-2026-47848: Reactor Netty WebSocket Client Leaks Credentials On Redirect

Published Aug 26, 2026
·
Updated

In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

Affected Software

3 affected components
Reactor Reactor Netty WebSocket Client>=1.3.0<=1.3.6
Reactor Reactor Netty WebSocket Client>=1.1.0<=1.2.18
Reactor Reactor Netty WebSocket Client<=1.0.52

Event History

Aug 26, 2026
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverity

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Only Reactor Netty WebSocket client deployments are affected, and only when the underlying HTTP client has been explicitly configured to follow redirects. The vulnerable behavior requires a WebSocket handshake redirect to a different origin.

2

What must an attacker or malicious endpoint do to trigger credential exposure?

The WebSocket handshake must be redirected to a different origin while redirect following is enabled. Exploitation also requires a user interaction, as reflected by the UI:R vector.

3

How can I determine whether my application may be affected?

Review WebSocket client configuration for explicit HTTP redirect following, then identify whether handshake endpoints can redirect clients to another origin. Versions 1.3.0 through 1.3.6, 1.1.0 through 1.2.18, and 1.0.52 or earlier are listed as affected.

4

What can be done if updating is not immediately possible?

Disable redirect following for the HTTP client used by the Reactor Netty WebSocket client, or prevent WebSocket handshake redirects to different origins. This removes the stated condition required for credential leakage.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203