Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreIn Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition.
If a stream remains active for an extended period and experiences specific downstream backpressure conditions, an internal state tracking flaw can be triggered. This causes the stream to permanently hang and stop processing elements without raising an error. An attacker could exploit this by maintaining long-lived connections and manipulating read speeds, potentially leading to resource exhaustion and a denial of service.
Reactor Core:
| Fix version | Availability |
|---|---|
| 3.8.7 | OSS |
| 3.8.6.1 | Enterprise Support Only |
| 3.7.20 | Enterprise Support Only |
| 3.4.42 | Enterprise Support Only |
No further mitigation steps are necessary.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy