Visit NES for Reactor Netty Home Page

NES for Reactor Netty 1.0.x Release Notes

2 versions

Comprehensive release notes and changelog for NES for Reactor Netty 1.0.x, including security patches, bug fixes, and feature updates across all supported versions.

Sep 21, 2026
Latest: 1.0.50
2 Patched Vulnerabilities
VEX Statements

September 2026

Full Version:
1.0.48-reactor-netty-1.0.50

Security Fixes

  • Credential leak on chained redirects in the HTTP client, where the sensitive header stripping guard compared each redirect target against the preceding hop rather than the original request URI, so a redirect within the same authority restored the original credentials (CVE-2025-22227, High).
  • Credential leak on protocol downgrade redirects in the HTTP client, where the same guard compared targets by remote address only and ignored the scheme, so an https to http downgrade on the same host and port left the credentials in place and sent them unencrypted (CVE-2026-41715, High).

1.0.49

Released Sep 16, 2026
Full Version:
1.0.48-reactor-netty-1.0.49

Notes

  • This release originates from the open-source Reactor Netty repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.