PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107230 AsyncHttpClient CVE debrief

The AsyncHttpClient library, used in Java applications for executing HTTP requests, had a vulnerability in versions 2.0.0 through 3.0.14. This issue allowed pooled connections to be shared across different authentication mechanisms like NTLM, Negotiate, and proxy logins, potentially exposing data or authority of one identity to another. The vulnerability is fixed in version 3.0.14.

Vendor
AsyncHttpClient
Product
async-http-client
CVSS
HIGH 7.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders and developers of Java applications using AsyncHttpClient, particularly those involving NTLM, Negotiate, or proxy logins, should assess exposure and prioritize updates. This includes operators managing affected systems, platform administrators, vulnerability management teams, and security teams responsible for ensuring the security and integrity of Java applications that utilize AsyncHttpClient.

Why it matters

CVE-2026-107230 is a high-severity vulnerability in AsyncHttpClient that could allow data exposure or unauthorized actions. Defenders should prioritize updates and assess exposure in their Java applications.

  • Potential data exposure across different identities
  • Possible unauthorized actions under a different identity
  • Need for verification of current AsyncHttpClient version
  • Priority for updating to version 3.0.14 or later

Technical summary

The AsyncHttpClient library, used in Java applications, had a vulnerability allowing pooled connections to be shared across NTLM, Negotiate, and proxy logins. This could expose data or authority of one identity to another. The issue arises from connection-pool partitioning omitting identity-defining fields for certain authentication mechanisms. The vulnerability is fixed in version 3.0.14. Defenders should prioritize updating to this version or later to mitigate this vulnerability. They should assess exposure in their Java applications that use AsyncHttpClient, particularly those involving NTLM, Negotiate, or proxy logins. Verification of the current version and inventory checks for affected versions are also  

Defensive priority

Defenders should prioritize updating to version 3.0.14 or later to mitigate this vulnerability. They should assess exposure in their Java applications that use AsyncHttpClient, particularly those involving NTLM, Negotiate, or proxy logins. Verification of the current version and inventory checks for affected versions are recommended.

Recommended defensive actions

  • Update AsyncHttpClient to version 3.0.14 or later
  • Assess exposure in Java applications using AsyncHttpClient
  • Verify current version and perform inventory checks for affected versions
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability in AsyncHttpClient. The issue arises from connection-pool partitioning omitting identity-defining fields for certain authentication mechanisms, allowing for potential data exposure or unauthorized actions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107230 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107230

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107230 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107230

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107230.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v2j5-22fr-j62r

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.