WebSocket Vulnerability in AsyncHttpClient Library for Java Applications
CVE-2026-107284
What is CVE-2026-107284?
The AsyncHttpClient library, commonly utilized in Java applications for handling HTTP requests and responses asynchronously, has a vulnerability related to WebSocket handshake procedures. Versions prior to 3.0.12 and 2.16.1 fail to terminate a handshake when the Sec-WebSocket-Accept value is either missing or invalid. This oversight allows the continuation of pipeline installations and onOpen deliveries, potentially enabling the acceptance of frames coalesced with an invalid 101 response from peers that didn’t properly validate the handshake. Consequently, HTTP requests may fail even as malicious frames could be delivered, jeopardizing the integrity of the application. It is critical for developers using earlier versions to update promptly to ensure the security of their applications.
Affected Version(s)
async-http-client >= 3.0.0, < 3.0.12 < 3.0.0, 3.0.12
async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1
