Authentication Bypass in AsyncHttpClient Library by AsyncHttpClient
CVE-2026-107230
What is CVE-2026-107230?
The AsyncHttpClient library allows Java applications to perform HTTP requests asynchronously. Versions from 2.0.0 to 3.0.14 have a vulnerability in connection-pool partitioning, failing to include crucial identity-defining fields when dealing with Kerberos, SPNEGO, NTLM, and authenticated proxy connections. As a result, logins lacking a configured principal or sharing user names can lead to unauthorized reuse of sockets, enabling one request to expose sensitive data or authority of another identity. This vulnerability impacts how user authentication is handled, particularly under conditions involving proxy logins. The issue has been resolved in version 3.0.14.
Affected Version(s)
async-http-client >= 3.0.0, < 3.0.14 < 3.0.0, 3.0.14
async-http-client >= 2.0.0, <= 2.16.1 <= 2.0.0, 2.16.1
