CVE-2026-47845
Received Received - Intake

Incorrect IP Address Evaluation in Reactor Netty HTTP Server with HAProxy Protocol

Vulnerability report for CVE-2026-47845, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: VMware

Description

In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
reactor_netty reactor_netty From 1.0.0 (inc) to 1.3.7 (exc)
reactor_netty reactor_netty From 1.1.0 (inc) to 1.2.19 (exc)
reactor_netty reactor_netty From 1.3.0 (inc) to 1.3.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability occurs in Reactor Netty HTTP Server when HAProxy Protocol is enabled. It causes the server to incorrectly evaluate the remote IP address of incoming connections. The issue only affects systems configured to use HAProxy Protocol.

Detection Guidance

Check if your Reactor Netty HTTP Server is running a vulnerable version (1.3.0-1.3.6, 1.1.0-1.2.18, or 1.0.52 and earlier) and verify if HAProxy Protocol is enabled. Use commands like 'java -jar your-app.jar --version' to check the version and review server configuration files for HAProxy Protocol settings.

Impact Analysis

The vulnerability could allow an attacker to manipulate IP-based access controls or logging. This might lead to unauthorized access or incorrect logging of client IPs, potentially bypassing security measures that rely on IP addresses.

Compliance Impact

This vulnerability may lead to incorrect evaluation of remote IP addresses when HAProxy Protocol is enabled. This could potentially affect compliance with GDPR or HIPAA by allowing unauthorized access or misidentification of users, though specific impacts depend on the application's use case and data handling.

Mitigation Strategies

Upgrade to a fixed version of Reactor Netty: 1.3.7 (OSS), 1.3.6.1 (Enterprise), 1.2.19 (Enterprise), or 1.0.53 (Enterprise). No additional mitigation steps are required after upgrading.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47845. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart