CVE-2025-22227 Information

Description

In some specific scenarios with chained redirects Reactor Netty HTTP client leaks credentials. In order for this to happen the HTTP client must have been explicitly configured to follow redirects.

Reference

https://spring.io/security/cve-2025-22227

CNNVD-202507-2117 (Published: 2025-07-16)

Share on: