CVE-2026-47857
Received Received - Intake

Denial of Service in Reactor Core via Flux.windowTimeout

Vulnerability report for CVE-2026-47857, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: VMware

Description

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and earlier

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
vmware reactor_core From 3.4.41 (inc) to 3.8.7 (exc)
vmware reactor_core From 3.5.0 (inc) to 3.7.19 (inc)
vmware reactor_core From 3.8.0 (inc) to 3.8.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Denial of Service (DoS) condition in Reactor Core affecting applications using the Flux.windowTimeout operator with fairBackpressure enabled. A flaw in internal state tracking can cause a stream to hang permanently without error if it remains active for a long time and experiences specific downstream backpressure conditions.

Detection Guidance

This vulnerability is specific to applications using Reactor Core with the Flux.windowTimeout operator and fairBackpressure enabled. Detection requires checking application code for usage of these components and versions. No direct network or system commands can detect this vulnerability as it is a logic flaw in the library.

Impact Analysis

An attacker could exploit this by maintaining long-lived connections and manipulating read speeds, potentially leading to resource exhaustion and a denial of service. This could disrupt application availability and performance.

Compliance Impact

This vulnerability primarily causes a Denial of Service (DoS) by hanging active streams without error, which could lead to resource exhaustion. While not directly tied to data breaches, prolonged service disruption may impact availability requirements under GDPR (Article 32) and HIPAA (Security Rule). However, the provided context does not specify direct compliance violations or data exposure risks.

Mitigation Strategies

Upgrade Reactor Core to fixed versions: 3.8.7 (OSS), 3.8.6.1 (Enterprise), 3.7.20 (Enterprise), or 3.4.42 (Enterprise). No additional mitigation steps are required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47857. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart