CVE-2020-5404

Executive Summary

CVE-2020-5404 exposes a credentials leak in Reactor Netty’s HttpClient (v0.9.x <0.9.5, v0.8.x <0.8.16) when redirects are enabled. An attacker can redirect a request to a different domain, causing the client to inadvertently send stored credentials to the new host. This flaw can lead to credential compromise in applications that rely on automatic redirect handling.


Authoritative CVE Metadata - CVSS Base Score: 5.9 (MEDIUM) - Published: 2020-03-03T18:15:12.157 - Last Modified: 2026-09-04T18:59:12.370

Original Description: The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.

"Don't ruin the present with the ruined past."

— Ellen Gilchrist
Source: NVD