reactor-netty-http is vulnerable to Denial of Service (DoS)
53
Medium Risk
reactor-netty-http consumes excessive memory when a client sends HTTP/1.1 pipelined requests on a single connection. A remote sender can degrade or exhaust the server by pipelining many requests. Availability of other connections is then reduced. The patch bounds memory used while handling pipelined requests.
You are affected if you are using a version that falls within the vulnerable range and the Reactor Netty HTTP server accepts HTTP/1.1 pipelined requests.
reactor-netty-http is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 1.3.6.
Upgrade the io.projectreactor.netty:reactor-netty-http library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant