CVE-2023-34054

Executive Summary

CVE-2023-34054 exposes a denial‑of‑service flaw in Reactor Netty HTTP Server (v1.1.x <1.1.13 and v1.0.x <1.0.39) when Micrometer integration is enabled. Attackers can send specially crafted HTTP requests that trigger resource exhaustion, halting the server. The issue is not yet listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 5.3 (MEDIUM) - Published: 2023-11-28T09:15:07.147 - Last Modified: 2026-09-04T18:59:12.370

Original Description:

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.

Specifically, an application is vulnerable if Reactor Netty HTTP Server built-in integration with Micrometer is enabled.

"The important thing is this: to be able at any moment to sacrifice what we are for what we could become."

— Charles Dubois
Source: NVD