5.3

CVE-2026-47845

Reactor Netty HTTP Server may incorrectly evaluate proxy addresses

In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol.
Reactor Netty 1.3.0 - 1.3.6
Reactor Netty 1.1.0 - 1.2.18
Reactor Netty 1.0.52 and earlier
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Broadcom ≫ Reactor Netty Version < 1.0.53
Broadcom ≫ Reactor Netty Version >= 1.1.0 < 1.2.19
Broadcom ≫ Reactor Netty Version >= 1.3.0 < 1.3.6.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.072
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
VMware 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-290 Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.