CVE-2023-34054: Broadcom Reactor Netty
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable if Reactor Netty HTTP Server built-in integration with Micrometer is enabled.
Affected products
- Broadcom Reactor Netty: before 1.0.39 (fixed in 1.0.39); from 1.1.0, before 1.1.13 (fixed in 1.1.13)
Published 2023-11-28. Last modified 2026-09-04.