{"id":"CVE-2026-47857","title":"In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition.\nReactor Core 3.8.0 - 3.8.6\nReactor Core 3.5.0 - 3.7.19\nReactor Core 3.4.41 and ea…","summary":"In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition.\nReactor Core 3.8.0 - 3.8.6\nReactor Core 3.5.0 - 3.7.19\nReactor Core 3.4.41 and ea…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-190","CWE-770"],"vendor":"broadcom","product":"reactor_core","affected":["reactor_core < 3.4.42","reactor_core >= 3.5.0, < 3.7.20","reactor_core >= 3.8.0, < 3.8.6.1"],"patched":["reactor_core 3.8.6.1"],"published":"2026-08-27","updated":"2026-09-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-47857","references":[{"url":"https://spring.io/security/cve-2026-47857","label":"security@vmware.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47857.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-47857"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2524774"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47857"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47857"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00222,"epssPercentile":0.13073,"ingestedAt":"2026-09-05T19:43:56.175Z","slug":"CVE-2026-47857","body":"## Overview\n\nIn Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition.\nReactor Core 3.8.0 - 3.8.6\nReactor Core 3.5.0 - 3.7.19\nReactor Core 3.4.41 and earlier\n\n## Affected\n\n- `reactor_core < 3.4.42`\n- `reactor_core >= 3.5.0, < 3.7.20`\n- `reactor_core >= 3.8.0, < 3.8.6.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `reactor_core 3.8.6.1`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Debezium 3, Red Hat Data Grid 8, Red Hat Fuse 7 · no fix planned: Exploit Intelligence, Red Hat Fuse 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Debezium 3, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47857.json)","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":32.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}