SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-47874

MEDIUM · CVSS 5.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Reactor Netty HTTP server is vulnerable to excessive memory consumption when handling HTTP/1.1 pipelined requests over a single connection. This can lead to performance degradation or potential denial of service for applications relying on affected versions (1.0.52 and earlier, 1.1.0 - 1.2.18, and 1.3.0 - 1.3.6). Organizations using these versions should prioritize patching to mitigate the risk of service interruptions.

CVE
CVE-2026-47874
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%

Original NVD Description

The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)