CVE-2026-107282 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.
Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, cross-host request replay updates the current request but leaves the target request and related proxy context pointing at the original origin. Connection-pool selection, CONNECT handling, realm selection, and TLS setup can consequently send the original host's path, Host header, Authorization credentials, or plaintext request to the replay destination. Documented ResponseFilter failover and retry paths can trigger the replay. This issue is fixed in versions 3.0.13 and 2.16.1.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCritical severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
AT
Present
Attack Requirements
PR
None
Privileges Required
UI
None
User Interaction
VC
High
Confidentiality (Vulnerable System)
VI
High
Integrity (Vulnerable System)
VA
None
Availability (Vulnerable System)
SC
High
Confidentiality (Subsequent System)
SI
High
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
Affected
- Vendor
- Maven
- Product
- org.asynchttpclient:async-http-client
Versions
- pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.13
- pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1
Stated as the source expressed them.
References
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/commit/15b254514a411623e5f1d8c99ea79c0f82f8a466
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/commit/bbc31aed3b044f9f7a126cf689a8c8d7ad2ae1cb
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-jmqq-x5g9-9p2w
- advisoryOSV GHSA-jmqq-x5g9-9p2whttps://osv.dev/vulnerability/GHSA-jmqq-x5g9-9p2w
- advisoryOSV advisoryhttps://nvd.nist.gov/vuln/detail/CVE-2026-107282
- vendorOSV packagehttps://github.com/AsyncHttpClient/async-http-client
Related threats
same CWE or vendorCVE-2026-107715 — The Mechanize library is used for automating interaction with websites.
CVE-2026-107715 · 2h ago
CVE-2026-107714 — The Mechanize library is used for automating interaction with websites.
CVE-2026-107714 · 2h ago
CVE-2026-107399 — The Mechanize library is used for automating interaction with websites.
CVE-2026-107399 · 2h ago
CVE-2026-107336 — Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive r…
CVE-2026-107336 · 6h ago
AsyncHttpClient: Cookies received over plaintext HTTP can plant, overwrite or delete Secure cookies set over HTTPS
CVE-2026-107226 · 8h ago
CVE-2026-105833 — EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account sc…
CVE-2026-105833 · 9h ago