PatchSiren cyber security CVE debrief
CVE-2026-107230 AsyncHttpClient CVE debrief
The AsyncHttpClient library, used in Java applications for executing HTTP requests, had a vulnerability in versions 2.0.0 through 3.0.14. This issue allowed pooled connections to be shared across different authentication mechanisms like NTLM, Negotiate, and proxy logins, potentially exposing data or authority of one identity to another. The vulnerability is fixed in version 3.0.14.
- Vendor
- AsyncHttpClient
- Product
- async-http-client
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders and developers of Java applications using AsyncHttpClient, particularly those involving NTLM, Negotiate, or proxy logins, should assess exposure and prioritize updates. This includes operators managing affected systems, platform administrators, vulnerability management teams, and security teams responsible for ensuring the security and integrity of Java applications that utilize AsyncHttpClient.
Why it matters
CVE-2026-107230 is a high-severity vulnerability in AsyncHttpClient that could allow data exposure or unauthorized actions. Defenders should prioritize updates and assess exposure in their Java applications.
- Potential data exposure across different identities
- Possible unauthorized actions under a different identity
- Need for verification of current AsyncHttpClient version
- Priority for updating to version 3.0.14 or later
Technical summary
The AsyncHttpClient library, used in Java applications, had a vulnerability allowing pooled connections to be shared across NTLM, Negotiate, and proxy logins. This could expose data or authority of one identity to another. The issue arises from connection-pool partitioning omitting identity-defining fields for certain authentication mechanisms. The vulnerability is fixed in version 3.0.14. Defenders should prioritize updating to this version or later to mitigate this vulnerability. They should assess exposure in their Java applications that use AsyncHttpClient, particularly those involving NTLM, Negotiate, or proxy logins. Verification of the current version and inventory checks for affected versions are also
Defensive priority
Defenders should prioritize updating to version 3.0.14 or later to mitigate this vulnerability. They should assess exposure in their Java applications that use AsyncHttpClient, particularly those involving NTLM, Negotiate, or proxy logins. Verification of the current version and inventory checks for affected versions are recommended.
Recommended defensive actions
- Update AsyncHttpClient to version 3.0.14 or later
- Assess exposure in Java applications using AsyncHttpClient
- Verify current version and perform inventory checks for affected versions
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability in AsyncHttpClient. The issue arises from connection-pool partitioning omitting identity-defining fields for certain authentication mechanisms, allowing for potential data exposure or unauthorized actions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107230 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107230
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107230 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107230
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107230.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v2j5-22fr-j62r
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.