GHSA-gpch-h32j-gx6x
GitHub Security Advisory
Insufficiently Protected Credentials in Reactor Netty
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.
Affected Packages
Maven
io.projectreactor.netty:reactor-netty-http
Affected versions:
0.9.0
(fixed in 0.9.5)
Maven
io.projectreactor.netty:reactor-netty-http
Affected versions:
0.8.0
(fixed in 0.8.16)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 1, 2025 6:32 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.