CVE-2023-34062: Broadcom Reactor Netty

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifically, an application is vulnerable if Reactor Netty HTTP Server is configured to serve static resources.

Affected products

  • Broadcom Reactor Netty: from 1.0.0, before 1.0.39 (fixed in 1.0.39); from 1.1.0, before 1.1.13 (fixed in 1.1.13)

Published 2023-11-15. Last modified 2026-09-04.