In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.
Affected versions:
Reactor Netty 1.0.0 through 1.0.51; 1.1.0 through 1.1.35; 1.2.0 through 1.2.17; 1.3.0 through 1.3.5.
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-41715 |
Configurations
No configuration.
History
09 Jun 2026, 05:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-09 05:16
Updated : 2026-06-09 13:49
NVD link : CVE-2026-41715
Mitre link : CVE-2026-41715
CVE.ORG link : CVE-2026-41715
JSON object : View
Products Affected
No product.
CWE
CWE-522
Insufficiently Protected Credentials
