Overview
About vulnerability
In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition.
If a stream remains active for an extended period and experiences specific downstream backpressure conditions, an internal state tracking flaw can be triggered. This causes the stream to permanently hang and stop processing elements without raising an error. An attacker could exploit this by maintaining long-lived connections and manipulating read speeds, potentially leading to resource exhaustion and a denial of service.
Details
- Affected product:
- Apache CXF , Apache Log4j , Netty , React , Spring , azure-sdk-for-java , camel , couchbase-jvm-clients-core-io , couchbase-jvm-clients-java-client , cypher-dsl , grails-core , grails-data-mapping , grails-gsp , grails-plugin-converters , infinispan , kotlinx.coroutines , lettuce , micronaut-cache , micronaut-core , micronaut-spring , neo4j-java-driver , pulsar , pulsar-client-reactive , r2dbc-pool , rsocket-java , tika
- Affected packages:
- Spring Framework @ 6.1.19 (+7620 more)