CVE-2025-22227: VMware Reactor Netty
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.
Affected products
- VMware Reactor Netty
Published 2025-07-16. Last modified 2026-06-17.