{"id":"CVE-2020-5404","aliases":["GHSA-gpch-h32j-gx6x"],"url":"https://o3.security/vulnerability/CVE-2020-5404","summary":"Insufficiently Protected Credentials in Reactor Netty","details":"The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.","published":"2020-03-03T18:15:12.157Z","modified":"2026-09-06T14:04:06.582353Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N"},"epss":{"score":0.00653,"percentile":0.4832,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"io.projectreactor.netty:reactor-netty-http","fixedVersion":"0.9.5"},{"ecosystem":"Maven","name":"io.projectreactor.netty:reactor-netty-http","fixedVersion":"0.8.16"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://pivotal.io/security/cve-2020-5404"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-5404"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-06T14:04:06.582353Z"}}