CVE-2020-5403
Executive Summary
Reactor Netty HttpServer (v0.9.3 & v0.9.4) fails to return a proper 400 response when a malformed URI is received; instead, a URISyntaxException triggers an abrupt connection close. This flaw can lead to service disruption or denial‑of‑service conditions for clients attempting to connect with invalid URLs.
Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2020-03-03T19:15:15.210 - Last Modified: 2026-09-04T18:59:12.370
Original Description: Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be closed prematurely instead of producing a 400 response.
"Learn wisdom from the ways of a seedling. A seedling which is never hardened off through stressful situations will never become a strong productive plant."
— Stephen Sigmund