PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107282 AsyncHttpClient CVE debrief

The AsyncHttpClient library, used in Java applications for executing HTTP requests, has a vulnerability prior to versions 3.0.13 and 2.16.1. This issue allows for cross-host request replay, which can lead to unintended exposure of sensitive information, including the original host's path, Host header, Authorization credentials, or plaintext request, when the request is replayed to a different host.

Vendor
AsyncHttpClient
Product
async-http-client
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders and developers using AsyncHttpClient in Java applications should be aware of this vulnerability and take steps to update to fixed versions. They should review affected applications and systems to ensure they are updated and secure. Operators and security teams should prioritize updating to fixed versions (3.0.13 or 2.16.1) and review compensating controls for exposed systems while remediation is scheduled and verified.

Why it matters

The AsyncHttpClient library has a critical vulnerability allowing cross-host request replay, potentially exposing sensitive information. Defenders should prioritize updating to fixed versions (3.0.13 or 2.16.1) and review affected applications.

  • Potential exposure of sensitive information, including the original host's path, Host header, Authorization credentials, or plaintext request.
  • Possible unauthorized access to sensitive data or systems.
  • Need for defenders to update to fixed versions of AsyncHttpClient to prevent potential exposure.
  • Verification of affected applications and systems to ensure they are updated and secure.

Technical summary

The AsyncHttpClient library has a vulnerability prior to versions 3.0.13 and 2.16.1, allowing for cross-host request replay and potential exposure of sensitive information, including the original host's path, Host header, Authorization credentials, or plaintext request. This issue can lead to unintended exposure of sensitive information when the request is replayed to a different host. Connection-pool selection, CONNECT handling, realm selection, and TLS setup can consequently send the original host's path, Host header, Authorization credentials, or plaintext request to the replay destination.

Defensive priority

Defenders should prioritize updating to fixed versions of AsyncHttpClient (3.0.13 or 2.16.1) to prevent potential exposure of sensitive information.

Recommended defensive actions

  • Update to AsyncHttpClient version 3.0.13 or 2.16.1
  • Review and update affected applications using AsyncHttpClient
  • Monitor for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, there is limited information on potential exploitation or victim impact. Defenders should verify affected applications and systems to ensure they are updated and secure. The AsyncHttpClient library, used in Java applications for executing HTTP requests, has a critical vulnerability allowing cross-host request replay, potentially exposing sensitive information. Evidence from the CVE Program record and source item confirm

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107282 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107282

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107282 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107282

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • AsyncHttpClient: Replay to a different host sends the original host request and credentials to t

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107282.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-jmqq-x5g9-9p2w

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/15b254514a411623e5f1d8c99ea79c0f82f8a466

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/bbc31aed3b044f9f7a126cf689a8c8d7ad2ae1cb

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.