SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-47845

MEDIUM · CVSS 5.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Reactor Netty HTTP Server versions 1.3.0 to 1.3.6, 1.1.0 to 1.2.18, and 1.0.52 and earlier may misinterpret remote IP addresses when the HAProxy Protocol is enabled, potentially leading to unauthorized access or misrouting of requests. Organizations utilizing these versions with HAProxy Protocol should prioritize patching to mitigate the risk of exposure. This vulnerability is particularly relevant for developers and system administrators managing applications that rely on Reactor Netty for HTTP server functionality.

CVE
CVE-2026-47845
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%

Original NVD Description

In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)