Connection Pool Vulnerability in AsyncHttpClient Library from AsyncHttpClient
CVE-2026-107281

7.6HIGH

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-107281?

The AsyncHttpClient library has a vulnerability where the connection pool management enables the reuse of authenticated sockets for different requests under certain authentication schemes. Specifically, connection-oriented NTLM and Negotiate authentication methods allow a pooled socket authenticated for one user to be reused by another request, which leads the server to execute subsequent requests as the first authenticated identity. This flaw does not affect Basic and Digest authentication as these methods authenticate each request individually. The vulnerability is mitigated in versions 3.0.13 and 2.16.1.

Affected Version(s)

async-http-client >= 3.0.0, < 3.0.13 < 3.0.0, 3.0.13

async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.