CVE-2022-31684

Executive Summary

CVE-2022-31684 affects Reactor Netty HTTP Server (v1.0.11‑1.0.23). When WARN‑level logging is enabled, the server may log request headers for certain malformed HTTP requests. These headers can contain valid access tokens, exposing them to anyone with log access. The vulnerability is limited to invalid requests and does not affect normal traffic. No CISA KEV listing currently.


Authoritative CVE Metadata - CVSS Base Score: 4.3 (MEDIUM) - Published: 2022-10-19T22:15:10.237 - Last Modified: 2026-09-04T18:59:12.370

Original Description: Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled.

"Act as if what you do makes a difference. It does."

— William James
Source: NVD