CVE-2026-47845
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/08/2026
Last modified:
27/08/2026
Description
In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol.<br />
Reactor Netty 1.3.0 - 1.3.6<br />
Reactor Netty 1.1.0 - 1.2.18<br />
Reactor Netty 1.0.52 and earlier
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM



