MEDIUMMaven

Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect

Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect

CVE-2026-41715Published 1 month agoUpdated 1 week agoSource: OSV

Affected packages

  • io.projectreactor.netty:reactor-netty1.3.0 → 1.3.6

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.17%
EPSS percentile
6.8%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 7%.

Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect | HackTribune