WebSocket Vulnerability in AsyncHttpClient Library for Java Applications
CVE-2026-107284

3.7LOW

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-107284?

The AsyncHttpClient library, commonly utilized in Java applications for handling HTTP requests and responses asynchronously, has a vulnerability related to WebSocket handshake procedures. Versions prior to 3.0.12 and 2.16.1 fail to terminate a handshake when the Sec-WebSocket-Accept value is either missing or invalid. This oversight allows the continuation of pipeline installations and onOpen deliveries, potentially enabling the acceptance of frames coalesced with an invalid 101 response from peers that didn’t properly validate the handshake. Consequently, HTTP requests may fail even as malicious frames could be delivered, jeopardizing the integrity of the application. It is critical for developers using earlier versions to update promptly to ensure the security of their applications.

Affected Version(s)

async-http-client >= 3.0.0, < 3.0.12 < 3.0.0, 3.0.12

async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.