In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Specifically, an application is vulnerable if Reactor Netty HTTP Server built-in integration with Micrometer is enabled.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Reactor_netty | Pivotal | * | 1.0.39 (excluding) |
Reactor_netty | Pivotal | 1.1.0 (including) | 1.1.13 (excluding) |