Back to database
Schedule33Medium5.9VulnerabilityCVE-2026-107285No patch link observed

CVE-2026-107285 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.

Published Oct 7, 2026, 10:17 PM UTCIngested 1d agoSource NVD(cve-db)CVE-2026-107285

Description

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
5.9

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

High

Attack Complexity

PR

None

Privileges Required

UI

None

User Interaction

S

Unchanged

Scope

C

High

Confidentiality

I

None

Integrity

A

None

Availability

Affected

Vendor
Maven
Product
org.asynchttpclient:async-http-client

Versions

  • pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.12
  • pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1

Stated as the source expressed them.