CVE-2026-47863 - Reactor Core bufferTimeout fair-backpressure pipeline permanently hangs when upstream delivers items during an active flush
CVE ID :CVE-2026-47863
Published : Aug. 27, 2026, 1:17 a.m. | 3 hours, 12 minutes ago
Description :In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7.19 and earlier
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 27, 2026, 1:17 a.m. | 3 hours, 12 minutes ago
Description :In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7.19 and earlier
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...