CVE-2026-41715: Spring Reactor Netty

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Affected versions: Reactor Netty 1.0.0 through 1.0.51; 1.1.0 through 1.1.35; 1.2.0 through 1.2.17; 1.3.0 through 1.3.5.

Affected products

  • Spring Reactor Netty: from 1.0.0, before 1.0.52 (fixed in 1.0.52); from 1.1.0, before 1.1.36 (fixed in 1.1.36); from 1.2.0, before 1.2.17.1 (fixed in 1.2.17.1); from 1.3.0, before 1.3.15.1 (fixed in 1.3.15.1)

Published 2026-06-09. Last modified 2026-07-23.