reactor-core is vulnerable to Denial of Service (DoS)
59
Medium Risk
reactor-core Flux.windowTimeout with fair backpressure can hang after a 20-bit index wrap on a long-lived stream. A client that keeps the stream open and manipulates read speed can stop element processing without an error. Held subscriptions then exhaust resources. The patch prevents the wrap-around from permanently stalling the operator.
You are affected if you are using a version that falls within the vulnerable range and you use Flux.windowTimeout with fair backpressure enabled.
reactor-core is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 3.8.6.
Upgrade the io.projectreactor:reactor-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant