CVE-2025-22227

Updated on 16 Jul 2025

Severity

6.1 Medium severity

Details

CVSS score
6.1
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Overview

About vulnerability

In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.

Details

Affected product:
Netty , Spring , azure-sdk-for-java , rsocket-java , tika
Affected packages:
spring-boot-maven-plugin @ 3.2.12 (+767 more)
In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.

Fixes