GHSA-7w4x-4h67-pgmv · Severity: medium · Ecosystem: maven — Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens
Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled.
Conclusion & alert: CVE-2022-31684 is rated Low Risk (37.6/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.37%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.24% | 0.37% | +0.13% |
| 2 | 2025-11-18 | 0.37% | 0.24% | -0.13% |
| 3 | 2025-11-06 | — | 0.37% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.3 | 3.1 | MEDIUM |
|
2.8 | 1.4 | [email protected] |
| 4.3 | 3.1 | MEDIUM |
|
2.8 | 1.4 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-7w4x-4h67-pgmv · Severity: medium · Ecosystem: maven — Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2022-31684 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| pivotal | reactor_netty | >= 1.0.11, <= 1.0.23 | cpe:2.3:a:pivotal:reactor_netty:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://tanzu.vmware.com/security/cve-2022-31684 | Vendor Advisory |