PatchSiren cyber security CVE debrief
CVE-2026-107282 AsyncHttpClient CVE debrief
The AsyncHttpClient library, used in Java applications for executing HTTP requests, has a vulnerability prior to versions 3.0.13 and 2.16.1. This issue allows for cross-host request replay, which can lead to unintended exposure of sensitive information, including the original host's path, Host header, Authorization credentials, or plaintext request, when the request is replayed to a different host.
- Vendor
- AsyncHttpClient
- Product
- async-http-client
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders and developers using AsyncHttpClient in Java applications should be aware of this vulnerability and take steps to update to fixed versions. They should review affected applications and systems to ensure they are updated and secure. Operators and security teams should prioritize updating to fixed versions (3.0.13 or 2.16.1) and review compensating controls for exposed systems while remediation is scheduled and verified.
Why it matters
The AsyncHttpClient library has a critical vulnerability allowing cross-host request replay, potentially exposing sensitive information. Defenders should prioritize updating to fixed versions (3.0.13 or 2.16.1) and review affected applications.
- Potential exposure of sensitive information, including the original host's path, Host header, Authorization credentials, or plaintext request.
- Possible unauthorized access to sensitive data or systems.
- Need for defenders to update to fixed versions of AsyncHttpClient to prevent potential exposure.
- Verification of affected applications and systems to ensure they are updated and secure.
Technical summary
The AsyncHttpClient library has a vulnerability prior to versions 3.0.13 and 2.16.1, allowing for cross-host request replay and potential exposure of sensitive information, including the original host's path, Host header, Authorization credentials, or plaintext request. This issue can lead to unintended exposure of sensitive information when the request is replayed to a different host. Connection-pool selection, CONNECT handling, realm selection, and TLS setup can consequently send the original host's path, Host header, Authorization credentials, or plaintext request to the replay destination.
Defensive priority
Defenders should prioritize updating to fixed versions of AsyncHttpClient (3.0.13 or 2.16.1) to prevent potential exposure of sensitive information.
Recommended defensive actions
- Update to AsyncHttpClient version 3.0.13 or 2.16.1
- Review and update affected applications using AsyncHttpClient
- Monitor for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, there is limited information on potential exploitation or victim impact. Defenders should verify affected applications and systems to ensure they are updated and secure. The AsyncHttpClient library, used in Java applications for executing HTTP requests, has a critical vulnerability allowing cross-host request replay, potentially exposing sensitive information. Evidence from the CVE Program record and source item confirm
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107282 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107282
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107282 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107282
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
AsyncHttpClient: Replay to a different host sends the original host request and credentials to t
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107282.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-jmqq-x5g9-9p2w
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/commit/15b254514a411623e5f1d8c99ea79c0f82f8a466
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/commit/bbc31aed3b044f9f7a126cf689a8c8d7ad2ae1cb
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.