Impact
Reactor Netty may incorrectly reuse a previously configured DNS resolver when multiple clients with differing DNS resolver settings are active. This flaw causes traffic to be routed incorrectly, which could lead to requests being sent to the wrong destinations or services. The defensive weakness arises from improper initialization of DNS resolver instances and is related to the Common Weakness enumeration CWE-665.
Affected Systems
Spring Reactor Netty versions 1.3.0 through 1.3.6, 1.1.0 through 1.2.18, and 1.0.52 and earlier are impacted by this issue.
Risk and Exploitability
The CVSS score of 3.7 indicates a low severity, and an EPSS score is not available, suggesting limited evidence of exploitation. The vulnerability is not listed in the CISA KEV catalogue. The likely attack vector requires the attacker to manipulate DNS resolver configuration in an environment where multiple Reactor Netty instances share the same resolver, or to influence the application’s DNS configuration at deployment time. While the impact is primarily availability or routing integrity, a sophisticated adversary could leverage misrouted traffic for data exfiltration or denial of service attacks.
OpenCVE Enrichment