reactor-netty-core is vulnerable to Improper Restriction of Communication Channel
37
Low Risk
reactor-netty-core can reuse a previously configured DNS resolver when multiple clients are created with different resolver settings. Traffic may then be resolved and routed to an unintended destination. This requires dynamically created clients such as HttpClient or TcpClient with custom DNS configuration. The patch keeps DNS resolvers isolated per client.
You are affected if you are using a version that falls within the vulnerable range and the application dynamically creates multiple Reactor Netty clients with different DNS resolver configurations.
reactor-netty-core is vulnerable to Improper Restriction of Communication Channel in versions 0.0.1 - 1.3.6.
Upgrade the io.projectreactor.netty:reactor-netty-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant