Back to database
Schedule52Critical9.4VulnerabilityCVE-2026-107282No patch link observed

CVE-2026-107282 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.

Published Oct 7, 2026, 10:17 PM UTCIngested 1d agoSource NVD(cve-db)CVE-2026-107282

Description

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, cross-host request replay updates the current request but leaves the target request and related proxy context pointing at the original origin. Connection-pool selection, CONNECT handling, realm selection, and TLS setup can consequently send the original host's path, Host header, Authorization credentials, or plaintext request to the replay destination. Documented ResponseFilter failover and retry paths can trigger the replay. This issue is fixed in versions 3.0.13 and 2.16.1.

CVSS v4.0 base metrics

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
9.4

Critical severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

High

Attack Complexity

AT

Present

Attack Requirements

PR

None

Privileges Required

UI

None

User Interaction

VC

High

Confidentiality (Vulnerable System)

VI

High

Integrity (Vulnerable System)

VA

None

Availability (Vulnerable System)

SC

High

Confidentiality (Subsequent System)

SI

High

Integrity (Subsequent System)

SA

None

Availability (Subsequent System)

Affected

Vendor
Maven
Product
org.asynchttpclient:async-http-client

Versions

  • pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.13
  • pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1

Stated as the source expressed them.