Connection Pool Vulnerability in AsyncHttpClient Library from AsyncHttpClient
CVE-2026-107281
7.6HIGH
What is CVE-2026-107281?
The AsyncHttpClient library has a vulnerability where the connection pool management enables the reuse of authenticated sockets for different requests under certain authentication schemes. Specifically, connection-oriented NTLM and Negotiate authentication methods allow a pooled socket authenticated for one user to be reused by another request, which leads the server to execute subsequent requests as the first authenticated identity. This flaw does not affect Basic and Digest authentication as these methods authenticate each request individually. The vulnerability is mitigated in versions 3.0.13 and 2.16.1.
Affected Version(s)
async-http-client >= 3.0.0, < 3.0.13 < 3.0.0, 3.0.13
async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1
