In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition.
Reactor Core 3.8.0 - 3.8.6
Reactor Core 3.5.0 - 3.7.19
Reactor Core 3.4.41 and earlier
Metrics
Affected Vendors & Products
References
History
Fri, 04 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Broadcom
Broadcom reactor Core |
|
| CPEs | cpe:2.3:a:broadcom:reactor_core:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Broadcom
Broadcom reactor Core |
Fri, 04 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 01 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring reactor Core |
|
| Vendors & Products |
Spring
Spring reactor Core |
Thu, 27 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-682 |
Thu, 27 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-190 | |
| Metrics |
ssvc
|
Thu, 27 Aug 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-682 |
Thu, 27 Aug 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and earlier | |
| Title | Reactor Core windowTimeout fair-backpressure stream hang due to 20-bit index wrap-around | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published: 2026-08-26T23:28:44.743Z
Updated: 2026-08-27T15:07:38.775Z
Reserved: 2026-05-20T10:00:55.156Z
Link: CVE-2026-47857
Updated: 2026-08-27T15:07:08.808Z
Status : Analyzed
Published: 2026-08-27T01:17:32.687
Modified: 2026-09-04T20:10:22.583
Link: CVE-2026-47857