Unknown · Reactor Netty · CVE-2026-47874
**Name of the Vulnerable Software and Affected Versions**
Reactor Netty versions 1.0.0 through 1.0.52
Reactor Netty versions 1.1.0 through 1.2.18
Reactor Netty versions 1.3.0 through 1.3.6
**Description**
An issue exists where the Reactor Netty HTTP server consumes an excessive amount of memory when a client sends HTTP/1.1 pipelined requests over a single connection. Pipelining is a technique where multiple HTTP requests are sent on a single TCP connection without waiting for the corresponding responses.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.