AsyncHttpClient: Thirteen Auth, Proxy, and WebSocket Flaws Disclosed Together
Key findings • Thirteen vulnerabilities in AsyncHttpClient disclosed on October 7, 2026, ranging from Low to Critical severity. • Issues span authentication bypasses, insecure proxy handling,…

Key findings
- Thirteen vulnerabilities in AsyncHttpClient disclosed on October 7, 2026, ranging from Low to Critical severity.
- Issues span authentication bypasses, insecure proxy handling, and WebSocket vulnerabilities.
- Critical flaw CVE-2026-107282 allows cross-host request replay due to improper proxy context handling.
- High severity CVE-2026-107227 impacts WebSocket security with unbounded permessage-deflate decompression.
- Patches are available in versions 3.0.12, 3.0.13, 3.0.14, and 2.16.1.
On October 7, 2026, a batch of thirteen vulnerabilities was disclosed for the AsyncHttpClient (AHC) library, affecting various aspects of its HTTP request handling and response processing. These vulnerabilities, disclosed within a one-hour window, range in severity from Low to High, with several critical issues impacting secure communication channels. The disclosures highlight weaknesses in authentication, proxy handling, WebSocket security, and cookie management within the library.
Several vulnerabilities center on authentication mechanisms. CVE-2026-107281, a High severity flaw, involves an issue with the HTTP/1.1 connection-pool key that excludes the authenticated principal for NTLM and Negotiate authentication, potentially allowing a pooled socket authenticated to one host to be used for another. Similarly, CVE-2026-107230 (High, CVSSv3 7.4) details how connection-pool partitioning omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections, leading to potential security bypasses. CVE-2026-107279 (High) describes a scenario where mutual-authentication verification is skipped when a peer offers only Digest with qop=auth-int. Additionally, CVE-2026-107231 (High) points out that a Digest challenge lacking a usable nonce can be treated as a Basic challenge, allowing a malicious party to misrepresent the challenge type.
Proxy handling and request replay also present security concerns. CVE-2026-107282 (Critical) addresses a flaw where cross-host request replay updates the current request but leaves the target request and proxy context pointing at the original origin, potentially leading to unintended requests being replayed. CVE-2026-107285 (Medium) notes that while proxied WebSocket requests are carried through CONNECT, the decision to attach proxy authentication is made after the fact, potentially exposing sensitive information. CVE-2026-107232 (High, CVSSv3 7.5) indicates that the client infers the existence of an HTTP proxy tunnel from the last request method rather than the CONNECT result, which could lead to incorrect tunnel assumptions after a proxy rejects a CONNECT request.
WebSocket security and cookie handling are also affected. CVE-2026-107227 (High, CVSSv3 7.5) reveals an unbounded permessage-deflate decompression in WebSocket when compression is enabled, potentially leading to denial-of-service conditions. CVE-2026-107284 (Low) describes a WebSocket handshake that, while aborting on invalid headers, proceeds with pipeline installation and onOpen delivery, potentially exposing the application to unexpected states. On the cookie front, CVE-2026-107280 (Medium) highlights that the ThreadSafeCookieStore validates Domain attributes without rejecting public suffixes, allowing hosts beneath suffixes like "co.uk" to set cookies for unintended domains. CVE-2026-107229 (Medium, CVSSv3 4.0) further details incomplete validation of cookie Domain attributes in ThreadSafeCookieStore, missing crucial rules for private sections and default public suffixes. CVE-2026-107228 (Medium, CVSSv3 6.8) points out that the enabled-by-default cookie store can overwrite explicitly supplied Cookie headers when the store contributes any cookie for the target host.
The vulnerabilities were patched in AsyncHttpClient versions 3.0.12, 3.0.13, 3.0.14, and 2.16.1, depending on the specific CVE. Users are strongly advised to update to the latest available versions to mitigate these security risks.
This coordinated disclosure of thirteen vulnerabilities underscores the importance of regularly updating the AsyncHttpClient library. The breadth of issues, spanning authentication, proxying, and WebSocket handling, indicates a need for thorough security reviews of network-dependent libraries. Developers relying on AHC should prioritize updating their dependencies to the patched versions to protect their applications from potential exploitation.
CVE-2026-107285 CVE-2026-107284 CVE-2026-107283 CVE-2026-107282 CVE-2026-107281 CVE-2026-107280 CVE-2026-107279 CVE-2026-107232 CVE-2026-107231 CVE-2026-107230 CVE-2026-107229 CVE-2026-107228 CVE-2026-107227