CVE-2025-22227
ADVISORY - githubSummary
In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.
Common Weakness Enumeration (CWE)
Exposure of Sensitive Information to an Unauthorized Actor
Exposure of Sensitive Information to an Unauthorized Actor
URL Redirection to Untrusted Site ('Open Redirect')
NIST
2.8
CVSS SCORE
6.1mediumGitHub
2.8
CVSS SCORE
6.1mediumRed Hat
2.8
CVSS SCORE
6.1mediumChainguard
CGA-2v33-rvrh-gpqf
-
Chainguard
CGA-38vg-h32c-rmfx
-
Chainguard
CGA-3w43-2hgx-fwmf
-
Chainguard
CGA-47cf-62p3-xgpr
-
Chainguard
CGA-548c-v35h-56h7
-
Chainguard
CGA-5hqf-6hh7-c6j6
-
Chainguard
CGA-6gj3-jxj6-wjw9
-
Chainguard
CGA-8f9f-g9g4-f9fr
-
Chainguard
CGA-8wv5-4jqg-gf53
-
Chainguard
CGA-9rc9-5wg2-7836
-
Chainguard
CGA-fp2v-jv6c-6j6h
-
Chainguard
CGA-g92c-j3hf-x9fm
-
Chainguard
CGA-h4h5-h224-vvwf
-
Chainguard
CGA-m62x-mwj9-p883
-
Chainguard
CGA-mqgm-4cp6-3vvj
-
Chainguard
CGA-qjf7-4cq7-9v8j
-
Chainguard
CGA-r9fm-w5hp-2crg
-
Chainguard
CGA-vjg7-q739-x6vj
-
minimos
MINI-24p8-3rh2-7fvh
-
minimos
MINI-2f75-3q62-gfm3
-
minimos
MINI-6mj8-hp3x-pgcc
-
minimos
MINI-7wc4-vmc2-3hh8
-
minimos
MINI-856j-xm2f-5rmm
-
minimos
MINI-8prq-99p4-hj65
-
minimos
MINI-8wxj-mqcp-whxm
-
minimos
MINI-9h6x-xjw5-74fc
-
minimos
MINI-jf62-j2wv-qr55
-
minimos
MINI-p6f7-mh23-xw6q
-
minimos
MINI-wpm8-9w82-9h8h
-
minimos
MINI-x637-728g-2rpp
-