Cleartext Transmission of Sensitive Information Affecting io.projectreactor.netty:reactor-netty-http package, versions [, 1.2.18)[1.3.0-M1, 1.3.6)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-IOPROJECTREACTORNETTY-17260961
  • published9 Jun 2026
  • disclosed8 Jun 2026
  • creditYu Bao (yubao@paypal.com)

Introduced: 8 Jun 2026

NewCVE-2026-41715  (opens in a new tab)
CWE-319  (opens in a new tab)

How to fix?

Upgrade io.projectreactor.netty:reactor-netty-http to version 1.2.18, 1.3.6 or higher.

Overview

Affected versions of this package are vulnerable to Cleartext Transmission of Sensitive Information via HTTP redirect handling in the HTTP client. An attacker can obtain sensitive credentials by causing a client configured to automatically follow redirects to follow a redirect from a secure HTTPS endpoint to an insecure HTTP endpoint, resulting in the disclosure of authentication information over an unencrypted connection.

Note: This is only exploitable if the Reactor Netty HTTP client has been explicitly configured to follow redirects.

CVSS Base Scores

version 4.0
version 3.1