CVE-2026-47848: Broadcom Reactor Netty
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier
Affected products
- Broadcom Reactor Netty: before 1.0.53 (fixed in 1.0.53); from 1.1.0, before 1.2.19 (fixed in 1.2.19); from 1.3.0, before 1.3.6.1 (fixed in 1.3.6.1)
Published 2026-08-26. Last modified 2026-09-04.