Cross-Host Request Replay Vulnerability in AsyncHttpClient Library
CVE-2026-107282
9.4CRITICAL
What is CVE-2026-107282?
The AsyncHttpClient library, utilized by Java applications for executing HTTP requests, has a vulnerability that affects versions prior to 3.0.13 and 2.16.1. This issue allows for the possibility of cross-host request replay, where connection-pool selection and handling can inadvertently transmit sensitive information—including the original host's path, Host header, and authorization credentials—to unintended destinations. This can occur due to improper handling of the proxy context during failover and retry paths. Users are strongly advised to upgrade to the fixed versions to mitigate this risk.
Affected Version(s)
async-http-client >= 3.0.0, < 3.0.13 < 3.0.0, 3.0.13
async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1
