PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47845 Spring CVE debrief

Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. This occurs in specific scenarios and requires the application to be configured to use HAProxy Protocol. Affected versions include Reactor Netty 1.3.0 - 1.3.6, 1.1.0 - 1.2.18, and 1.0.52 and earlier. The vulnerability has a medium severity with a CVSS score of 5.3. Users should review their application configurations and update to a non-vulnerable version if necessary.

Vendor
Spring
Product
Reactor Netty
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-27
Original CVE updated
2026-09-04
Advisory published
2026-08-27
Advisory updated
2026-09-04

Who should care

Users of Reactor Netty versions 1.3.0 - 1.3.6, 1.1.0 - 1.2.18, and 1.0.52 and earlier who utilize HAProxy Protocol in their applications should be aware of this vulnerability. This includes developers, security teams, and operators who manage applications relying on Reactor Netty for HTTP server functionality. Reviewing application configurations and ensuring updates to non-vulnerable versions are crucial steps in mitigating potential risks associated with this vulnerability. Additionally, monitoring for potential IP address mis-evaluation scenarios is recommended to ensure the security posture of affected systems is maintained. It is also essential for users to verify the HAProxy Protocol usage in their applications and assess the potential impact on their security configurations. Furthermore, users should consider implementing compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. Regularly reviewing relevant monitoring, detection, and logs for exposed assets that need extra review is also advised to ensure that potential security incidents are promptly identified and addressed. Lastly, confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up is vital to ensure a coordinated and effective response to this vulnerability. This involves coordinating with relevant stakeholders, including developers, security teams, and operators, to ensure that all necessary steps are taken to mitigate the risks associated with this vulnerability. By taking these steps, users can help ensure the security and integrity of their applications and systems that rely on Reactor Netty for HTTP server functionality. Users should also consider reviewing compensating controls for exposed systems while remediation is scheduled and verified. This may include implementing additional security measures, such as network segmentation, access controls, or intrusion detection systems, to reduce the potential impact of a successful exploit. Furthermore, users should review and update their incident response plan

Technical summary

The Reactor Netty HTTP Server incorrectly evaluates the remote IP address in specific scenarios when HAProxy Protocol is enabled. This requires the application to be configured to use HAProxy Protocol. Affected versions are Reactor Netty 1.3.0 - 1.3.6, 1.1.0 - 1.2.18, and 1.0.52 and earlier. The issue arises from the server's inability to properly assess the remote IP address, potentially leading to security misconfigurations. Users should verify their application configurations and update to a patched version.

Defensive priority

Medium priority due to potential for IP address mis-evaluation in specific HAProxy Protocol scenarios.

Recommended defensive actions

  • Review and update Reactor Netty to version 1.3.7 or later, 1.2.19 or later, or 1.0.53 or later.
  • Verify application configuration for HAProxy Protocol usage.
  • Monitor for potential IP address mis-evaluation scenarios.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

Evidence from official CVE Program record and NVD vulnerability detail page supports the existence of the vulnerability in Reactor Netty versions 1.3.0 - 1.3.6, 1.1.0 - 1.2.18, and 1.0.52 and earlier. Limited detail available on exploitability and potential impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47845 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47845

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47845 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47845

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.