CVE-2026-107285 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.
Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
High
Confidentiality
I
None
Integrity
A
None
Availability
Affected
- Vendor
- Maven
- Product
- org.asynchttpclient:async-http-client
Versions
- pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.12
- pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1
Stated as the source expressed them.
References
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/commit/6e9cb75a9b7259353f983fc90ca28b1da3742e18
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/commit/c4feab0f7f86d61505a48e40d383c8a375a22e18
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-3wp9-xfwm-rjjf
- advisoryOSV GHSA-3wp9-xfwm-rjjfhttps://osv.dev/vulnerability/GHSA-3wp9-xfwm-rjjf
- advisoryOSV advisoryhttps://nvd.nist.gov/vuln/detail/CVE-2026-107285
- vendorOSV packagehttps://github.com/AsyncHttpClient/async-http-client
Related threats
same CWE or vendorCVE-2026-107715 — The Mechanize library is used for automating interaction with websites.
CVE-2026-107715 · 2h ago
CVE-2026-107714 — The Mechanize library is used for automating interaction with websites.
CVE-2026-107714 · 2h ago
CVE-2026-107399 — The Mechanize library is used for automating interaction with websites.
CVE-2026-107399 · 2h ago
AsyncHttpClient: Cookies received over plaintext HTTP can plant, overwrite or delete Secure cookies set over HTTPS
CVE-2026-107226 · 8h ago
CVE-2026-105833 — EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account sc…
CVE-2026-105833 · 9h ago
CVE-2026-104704 — Progressive Robot hMailServer 6.0.0 through 6.3.5 does not enforce TLS for outbound SMTP delivery to a mail exchanger whose DNSSEC-validated TLSA r…
CVE-2026-104704 · 13h ago