CVE-2026-47845
Last modified
CVE-2026-47845 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Reactor Netty | < 1.0.53 |
| Broadcom | Reactor Netty | >= 1.1.0, < 1.2.19 |
| Broadcom | Reactor Netty | >= 1.3.0, < 1.3.6.1 |
References
- https://spring.io/security/cve-2026-47845Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-47845?
How severe is CVE-2026-47845?
How do I fix CVE-2026-47845?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4784A vulnerability was found in code-projects Simple Laundry Sy…9.8
- CVE-2026-47840A network attacker positioned between UAA and its LDAP direc…9.3
- CVE-2026-47841An application using Spring Security's WebAuthn support may …7.4
- CVE-2026-47842Applications using AesBytesEncryptor with the two-argument c…6.5
- CVE-2026-47843In specific scenarios involving multiple clients with differ…3.7
- CVE-2026-47844In specific scenarios, the Reactor Netty HTTP Server may lea…3.7
- CVE-2026-47846Bitnami Cassandra container images are affected by a retaine…9.8
- CVE-2026-47847Bitnami MariaDB Galera container images and Helm chart are a…5.3
- CVE-2026-47848In specific scenarios involving WebSocket handshake redirect…6.1
- CVE-2026-47849Spring Data REST does not guard identifier (@Id) and version…7.1
- CVE-2026-4785The LatePoint – Calendar Booking Plugin for Appointments and…6.4
- CVE-2026-47850Spring Data REST does not preserve the persisted version (@V…4.3
Are you affected by CVE-2026-47845?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
