CVE-2026-47857 | Spring Reactor Core up to 3.4.41/3.7.19/3.8.6 Window Timeout Flux.windowTimeout fairBackpressure integer overflow
A vulnerability classified as problematic has been found in Spring Reactor Core up to 3.4.41/3.7.19/3.8.6. Affected by this issue is the function Flux.windowTimeout of the component Window Timeout. Performing a manipulation of the argument fairBackpressure results in integer overflow.
This vulnerability is known as CVE-2026-47857. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More