GHSA-pfc9-2cqg-9wq6

Suggest an improvement
Source
https://github.com/advisories/GHSA-pfc9-2cqg-9wq6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-pfc9-2cqg-9wq6/GHSA-pfc9-2cqg-9wq6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pfc9-2cqg-9wq6
Aliases
  • CVE-2026-41715
Published
2026-06-09T06:31:57Z
Modified
2026-07-29T18:41:44Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect
Details

In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.

Affected versions: Reactor Netty 1.0.0 through 1.0.51; 1.1.0 through 1.1.35; 1.2.0 through 1.2.17; 1.3.0 through 1.3.5.

Database specific
{
    "cwe_ids": [
        "CWE-522"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-29T18:18:20Z",
    "nvd_published_at": "2026-06-09T05:16:35Z",
    "severity": "MODERATE"
}
References

Affected packages

Maven
io.projectreactor.netty:reactor-netty

Package

Name
io.projectreactor.netty:reactor-netty
View open source insights on deps.dev
Purl
pkg:maven/io.projectreactor.netty/reactor-netty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.3.0
Fixed
1.3.6

Affected versions

1.*
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5

Database specific

last_known_affected_version_range
"<= 1.3.5"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-pfc9-2cqg-9wq6/GHSA-pfc9-2cqg-9wq6.json"
io.projectreactor.netty:reactor-netty

Package

Name
io.projectreactor.netty:reactor-netty
View open source insights on deps.dev
Purl
pkg:maven/io.projectreactor.netty/reactor-netty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.2.0
Fixed
1.2.18

Affected versions

1.*
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17

Database specific

last_known_affected_version_range
"<= 1.2.17"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-pfc9-2cqg-9wq6/GHSA-pfc9-2cqg-9wq6.json"
io.projectreactor.netty:reactor-netty

Package

Name
io.projectreactor.netty:reactor-netty
View open source insights on deps.dev
Purl
pkg:maven/io.projectreactor.netty/reactor-netty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Last Affected
1.1.31

Affected versions

1.*
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.10
1.1.11
1.1.12
1.1.13
1.1.14
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
1.1.31

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-pfc9-2cqg-9wq6/GHSA-pfc9-2cqg-9wq6.json"
io.projectreactor.netty:reactor-netty

Package

Name
io.projectreactor.netty:reactor-netty
View open source insights on deps.dev
Purl
pkg:maven/io.projectreactor.netty/reactor-netty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Last Affected
1.0.48

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.20
1.0.21
1.0.22
1.0.23
1.0.24
1.0.25
1.0.26
1.0.27
1.0.28
1.0.29
1.0.30
1.0.31
1.0.32
1.0.33
1.0.34
1.0.35
1.0.36
1.0.37
1.0.38
1.0.39
1.0.40
1.0.41
1.0.42
1.0.43
1.0.44
1.0.45
1.0.46
1.0.47
1.0.48

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-pfc9-2cqg-9wq6/GHSA-pfc9-2cqg-9wq6.json"