CVE-2026-41715EPSS p13.8%
CVE-2026-41715CVE-2026-41715
Description
In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.
Affected versions:
Reactor Netty 1.0.0 through 1.0.51; 1.1.0 through 1.1.35; 1.2.0 through 1.2.17; 1.3.0 through 1.3.5.
Scoring
| CVSS | 6.1 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 0.24% probability of exploitation · percentile 13.8% · 2026-10-06T12:00:23Z |
| Last modified | 2026-07-23 |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.