« Volver al listado

CVE-2026-41715

Estado: Pendiente de análisisMedia (6.1)—

In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.

Affected versions: Reactor Netty 1.0.0 through 1.0.51; 1.1.0 through 1.1.35; 1.2.0 through 1.2.17; 1.3.0 through 1.3.5.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-41715",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-41715",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-09T13:43:15.959618Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "Spring",
          "product": "Reactor Netty",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "1.0.52",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.1.0",
              "lessThan": "1.1.36",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.2.0",
              "lessThan": "1.2.17.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.3.0",
              "lessThan": "1.3.15.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-09T05:16:35.263",
  "references": [
    {
      "url": "https://spring.io/security/cve-2026-41715",
      "source": "security@vmware.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@vmware.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.\n\nAffected versions:\nReactor Netty 1.0.0 through 1.0.51; 1.1.0 through 1.1.35; 1.2.0 through 1.2.17; 1.3.0 through 1.3.5."
    },
    {
      "lang": "es",
      "value": "En escenarios específicos que involucran redirecciones HTTP de un endpoint seguro a uno inseguro, el cliente HTTP Reactor Netty puede filtrar credenciales. Para que esto ocurra, el cliente HTTP debe haber sido configurado explícitamente para seguir redirecciones.\n\nVersiones afectadas:\nReactor Netty 1.0.0 hasta 1.0.51; 1.1.0 hasta 1.1.35; 1.2.0 hasta 1.2.17; 1.3.0 hasta 1.3.5."
    }
  ],
  "lastModified": "2026-07-23T08:10:00.137",
  "sourceIdentifier": "security@vmware.com"
}