Description
In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configured DNS resolver.
Reactor Netty 1.3.0 - 1.3.6
Reactor Netty 1.1.0 - 1.2.18
Reactor Netty 1.0.52 and earlier
Published: 2026-08-26
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Reactor Netty may incorrectly reuse a previously configured DNS resolver when multiple clients with differing DNS resolver settings are active. This flaw causes traffic to be routed incorrectly, which could lead to requests being sent to the wrong destinations or services. The defensive weakness arises from improper initialization of DNS resolver instances and is related to the Common Weakness enumeration CWE-665.

Affected Systems

Spring Reactor Netty versions 1.3.0 through 1.3.6, 1.1.0 through 1.2.18, and 1.0.52 and earlier are impacted by this issue.

Risk and Exploitability

The CVSS score of 3.7 indicates a low severity, and an EPSS score is not available, suggesting limited evidence of exploitation. The vulnerability is not listed in the CISA KEV catalogue. The likely attack vector requires the attacker to manipulate DNS resolver configuration in an environment where multiple Reactor Netty instances share the same resolver, or to influence the application’s DNS configuration at deployment time. While the impact is primarily availability or routing integrity, a sophisticated adversary could leverage misrouted traffic for data exfiltration or denial of service attacks.

Generated by OpenCVE AI on August 26, 2026 at 20:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Reactor Netty to a version newer than 1.3.6, 1.2.18, or 1.0.52 to ensure the DNS resolver reuse bug is fixed
  • Configure each Reactor Netty client with its own DNS resolver instance instead of reusing a shared resolver to prevent accidental reuse
  • Monitor network traffic for anomalies or misrouted requests and verify that DNS resolution behavior matches application expectations

Generated by OpenCVE AI on August 26, 2026 at 20:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 26 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Spring
Spring reactor Netty
Weaknesses CWE-665
Vendors & Products Spring
Spring reactor Netty

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configured DNS resolver. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier
Title Reactor Netty may incorrectly route traffic due to DNS resolver reuse
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Spring Reactor Netty
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-08-26T19:45:10.489Z

Reserved: 2026-05-20T10:00:51.004Z

Link: CVE-2026-47843

cve-icon Vulnrichment

Updated: 2026-08-26T19:45:03.237Z

cve-icon NVD

Status : Received

Published: 2026-08-26T20:17:26.193

Modified: 2026-08-26T20:17:26.193

Link: CVE-2026-47843

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:45:03Z

Weaknesses