CVE-2026-47857: Broadcom Reactor Core

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and earlier

Affected products

  • Broadcom Reactor Core: before 3.4.42 (fixed in 3.4.42); from 3.5.0, before 3.7.20 (fixed in 3.7.20); from 3.8.0, before 3.8.6.1 (fixed in 3.8.6.1)

Published 2026-08-27. Last modified 2026-09-04.