We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-22227

CVE-2025-22227: Authentication Leak On Redirect With Reactor Netty HTTP Client



Description

In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.

Reserved 2025-01-02 | Published 2025-07-16 | Updated 2025-07-16 | Assigner vmware


MEDIUM: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Product status

Default status
unaffected

1.0.x before 1.0.49 (Reactor BOM 2020.0.48)
affected

1.1.x before 1.1.32 (Reactor BOM 2022.0.27 and 2023.0.20)
affected

1.2.x before 1.2.8 (Reactor BOM 2024.0.8)
affected

1.3.x before 1.3.0-M5 (Reactor BOM 2025.0.0-M5)
affected

References

spring.io/security/cve-2025-22227

cve.org (CVE-2025-22227)

nvd.nist.gov (CVE-2025-22227)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-22227

Support options

Helpdesk Chat, Email, Knowledgebase