Authentication Bypass in AsyncHttpClient Library by AsyncHttpClient
CVE-2026-107230

7.4HIGH

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-107230?

The AsyncHttpClient library allows Java applications to perform HTTP requests asynchronously. Versions from 2.0.0 to 3.0.14 have a vulnerability in connection-pool partitioning, failing to include crucial identity-defining fields when dealing with Kerberos, SPNEGO, NTLM, and authenticated proxy connections. As a result, logins lacking a configured principal or sharing user names can lead to unauthorized reuse of sockets, enabling one request to expose sensitive data or authority of another identity. This vulnerability impacts how user authentication is handled, particularly under conditions involving proxy logins. The issue has been resolved in version 3.0.14.

Affected Version(s)

async-http-client >= 3.0.0, < 3.0.14 < 3.0.0, 3.0.14

async-http-client >= 2.0.0, <= 2.16.1 <= 2.0.0, 2.16.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.