PatchSiren cyber security CVE debrief
CVE-2026-107284 AsyncHttpClient CVE debrief
The AsyncHttpClient library for Java allows easy execution of HTTP requests and asynchronous processing of HTTP responses. A vulnerability exists in versions prior to 3.0.12 and 2.16.1 where the WebSocketHandler.upgrade function aborts a handshake if the Sec-WebSocket-Accept value is missing or invalid. However, it continues into pipeline installation and onOpen delivery. This could potentially allow frames coalesced with the invalid 101 response to be decoded and delivered from a peer that did not prove the handshake, although the request future fails and the channel closes.
- Vendor
- AsyncHttpClient
- Product
- async-http-client
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Java applications using AsyncHttpClient, particularly those using versions prior to 3.0.12 and 2.16.1, should assess exposure and prioritize verification and potential upgrades.
Why it matters
The AsyncHttpClient library for Java has a vulnerability that could potentially allow frames to be decoded and delivered from untrusted peers. Defenders should prioritize verifying exposure in Java applications using affected versions and assess the need for upgrades or mitigations.
- Verification of AsyncHttpClient version and potential upgrade to fixed versions is necessary to prevent security implications.
- Defenders should assess exposure in Java applications using affected AsyncHttpClient versions.
- Invalid WebSocket handshakes could potentially allow delivery of frames from untrusted peers.
Technical summary
The AsyncHttpClient library for Java has a vulnerability in versions prior to 3.0.12 and 2.16.1. The WebSocketHandler.upgrade function does not properly handle invalid Sec-WebSocket-Accept values, potentially allowing frames to be decoded and delivered from untrusted peers. This issue can lead to security implications if not addressed. Defenders should prioritize verifying exposure in Java applications using affected versions and assess the need for upgrades or mitigations. The vulnerability is fixed in versions 3.0.12 and 2.16.1.
Defensive priority
Defenders should prioritize verifying exposure in Java applications using AsyncHttpClient versions prior to 3.0.12 and 2.16.1, and assess the need for upgrades or mitigations.
Recommended defensive actions
- Verify AsyncHttpClient version and upgrade to 3.0.12 or 2.16.1 if necessary
- Assess exposure in Java applications using affected AsyncHttpClient versions
- Monitor for potential security implications of invalid WebSocket handshakes
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and fixed versions. However, there is limited information on potential exploitation or victim impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107284 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107284
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107284 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107284
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-Accept check
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107284.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rwhr-j9rv-85f8
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/commit/75a278550aa9a980009d022fb4e635f9c8738c03
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/commit/ccdcaa627db6d96dcc42105212cb3ba5048bd7f9
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.