PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107284 AsyncHttpClient CVE debrief

The AsyncHttpClient library for Java allows easy execution of HTTP requests and asynchronous processing of HTTP responses. A vulnerability exists in versions prior to 3.0.12 and 2.16.1 where the WebSocketHandler.upgrade function aborts a handshake if the Sec-WebSocket-Accept value is missing or invalid. However, it continues into pipeline installation and onOpen delivery. This could potentially allow frames coalesced with the invalid 101 response to be decoded and delivered from a peer that did not prove the handshake, although the request future fails and the channel closes.

Vendor
AsyncHttpClient
Product
async-http-client
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Java applications using AsyncHttpClient, particularly those using versions prior to 3.0.12 and 2.16.1, should assess exposure and prioritize verification and potential upgrades.

Why it matters

The AsyncHttpClient library for Java has a vulnerability that could potentially allow frames to be decoded and delivered from untrusted peers. Defenders should prioritize verifying exposure in Java applications using affected versions and assess the need for upgrades or mitigations.

  • Verification of AsyncHttpClient version and potential upgrade to fixed versions is necessary to prevent security implications.
  • Defenders should assess exposure in Java applications using affected AsyncHttpClient versions.
  • Invalid WebSocket handshakes could potentially allow delivery of frames from untrusted peers.

Technical summary

The AsyncHttpClient library for Java has a vulnerability in versions prior to 3.0.12 and 2.16.1. The WebSocketHandler.upgrade function does not properly handle invalid Sec-WebSocket-Accept values, potentially allowing frames to be decoded and delivered from untrusted peers. This issue can lead to security implications if not addressed. Defenders should prioritize verifying exposure in Java applications using affected versions and assess the need for upgrades or mitigations. The vulnerability is fixed in versions 3.0.12 and 2.16.1.

Defensive priority

Defenders should prioritize verifying exposure in Java applications using AsyncHttpClient versions prior to 3.0.12 and 2.16.1, and assess the need for upgrades or mitigations.

Recommended defensive actions

  • Verify AsyncHttpClient version and upgrade to 3.0.12 or 2.16.1 if necessary
  • Assess exposure in Java applications using affected AsyncHttpClient versions
  • Monitor for potential security implications of invalid WebSocket handshakes
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, affected versions, and fixed versions. However, there is limited information on potential exploitation or victim impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107284 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107284

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107284 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107284

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-Accept check

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107284.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rwhr-j9rv-85f8

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/75a278550aa9a980009d022fb4e635f9c8738c03

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/ccdcaa627db6d96dcc42105212cb3ba5048bd7f9

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.