---
id: CVE-2026-47857
title: >-
  In Reactor Core, applications that use the Flux.windowTimeout operator with
  fairBackpressure enabled are vulnerable to a Denial of Service (DoS)
  condition.

  Reactor Core 3.8.0 - 3.8.6

  Reactor Core 3.5.0 - 3.7.19

  Reactor Core 3.4.41 and ea…
summary: >-
  In Reactor Core, applications that use the Flux.windowTimeout operator with
  fairBackpressure enabled are vulnerable to a Denial of Service (DoS)
  condition.

  Reactor Core 3.8.0 - 3.8.6

  Reactor Core 3.5.0 - 3.7.19

  Reactor Core 3.4.41 and ea…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-190
  - CWE-770
vendor: broadcom
product: reactor_core
affected:
  - reactor_core < 3.4.42
  - 'reactor_core >= 3.5.0, < 3.7.20'
  - 'reactor_core >= 3.8.0, < 3.8.6.1'
patched:
  - reactor_core 3.8.6.1
published: '2026-08-27'
updated: '2026-09-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-47857'
references:
  - url: 'https://spring.io/security/cve-2026-47857'
    label: security@vmware.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47857.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-47857'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2524774'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-47857'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-47857'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.00367
epssPercentile: 0.27755
ingestedAt: '2026-09-05T19:43:56.175Z'
---

## Overview

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition.
Reactor Core 3.8.0 - 3.8.6
Reactor Core 3.5.0 - 3.7.19
Reactor Core 3.4.41 and earlier

## Affected

- `reactor_core < 3.4.42`
- `reactor_core >= 3.5.0, < 3.7.20`
- `reactor_core >= 3.8.0, < 3.8.6.1`

## Remediation

Upgrade past the affected range:

- `reactor_core 3.8.6.1`

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Debezium 3, Red Hat Data Grid 8, Red Hat Fuse 7 · no fix planned: Exploit Intelligence, Red Hat Fuse 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Debezium 3, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47857.json)
