Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21595 | Reactor Netty HTTP is vulnerable to credential leaks during chained redirects |
Github GHSA |
GHSA-4q2v-9p7v-3v22 | Reactor Netty HTTP is vulnerable to credential leaks during chained redirects |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 23 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Jul 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 16 Jul 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Wed, 16 Jul 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. | |
| Title | CVE-2025-22227: Authentication Leak On Redirect With Reactor Netty HTTP Client | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-23T16:32:45.532Z
Reserved: 2025-01-02T04:29:59.191Z
Link: CVE-2025-22227
Updated: 2025-07-16T14:31:24.068Z
Status : Deferred
Published: 2025-07-16T10:15:27.787
Modified: 2026-06-17T08:45:45.027
Link: CVE-2025-22227
OpenCVE Enrichment
No data.
EUVD
Github GHSA