CVE-2026-47863: Reactor Core bufferTimeout fair-backpressure pipeline permanently hangs when upstream delivers items during an active flush
In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7.19 and earlier
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Reactor Coreto a version that resolves this vulnerability.Fixed in 3.7.19 and earlier - Upgrade
Upgrade
Reactor Coreto a version that resolves this vulnerability.Fixed in 3.8.0 - 3.8.6
Event History
Frequently Asked Questions
Which deployments should be prioritized for assessment?
Prioritize applications using Reactor Core versions 3.8.0 through 3.8.6, or 3.7.19 and earlier, where Flux.bufferTimeout is configured with fairBackpressure enabled.
Does exploitation require authentication or user interaction?
The supplied vector indicates the issue is network-reachable and requires neither privileges nor user interaction. Exploitation complexity is rated high.
What is the expected security impact?
The reported impact is availability loss through a denial of service. No confidentiality or integrity impact is indicated.