Cross-Host Request Replay Vulnerability in AsyncHttpClient Library
CVE-2026-107282

9.4CRITICAL

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-107282?

The AsyncHttpClient library, utilized by Java applications for executing HTTP requests, has a vulnerability that affects versions prior to 3.0.13 and 2.16.1. This issue allows for the possibility of cross-host request replay, where connection-pool selection and handling can inadvertently transmit sensitive information—including the original host's path, Host header, and authorization credentials—to unintended destinations. This can occur due to improper handling of the proxy context during failover and retry paths. Users are strongly advised to upgrade to the fixed versions to mitigate this risk.

Affected Version(s)

async-http-client >= 3.0.0, < 3.0.13 < 3.0.0, 3.0.13

async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.