CVE-2026-107230
Received Received - Intake

AsyncHttpClient Connection Pool Identity Spoofing Vulnerability

Vulnerability report for CVE-2026-107230, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections. Logins without a configured principal, proxy realms, identities sharing a user name, and SOCKS or CONNECT proxy logins can reuse a socket authenticated as a different identity. A later request is then executed under the first identity and can expose that identity's data or authority to another caller. In the affected execution path, SpnegoEngine, NTLM, Kerberos, SPNEGO, SOCKS, and CONNECT control or expose the vulnerable behavior. This issue is fixed in version 3.0.14.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
AsyncHttpClient async-http-client >= 3.0.0, < 3.0.14
AsyncHttpClient async-http-client >= 2.0.0, <= 2.16.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the AsyncHttpClient library in Java applications. It allows authenticated connections to be reused by different identities due to missing identity-defining fields in the connection pool. This means a later request could execute under a different user's identity, potentially exposing sensitive data or permissions.

Detection Guidance

This vulnerability is specific to the AsyncHttpClient library in Java applications. Detection requires checking if your application uses versions 2.0.0 to 3.0.13 of this library. Inspect dependency files like pom.xml or build.gradle for the vulnerable version.

Impact Analysis

An attacker could exploit this to access data or perform actions under another user's identity. This could lead to unauthorized data exposure, privilege escalation, or misuse of authenticated sessions. Systems using affected versions may allow cross-user data leakage.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to sensitive data, such as personal or health information. GDPR requires protecting personal data, while HIPAA mandates safeguarding health information. Exploitation could lead to breaches and non-compliance penalties.

Mitigation Strategies

Upgrade the AsyncHttpClient library to version 3.0.14 or later. Remove or replace any instances of versions between 2.0.0 and 3.0.13 in your project dependencies. Review network traffic for unauthorized identity reuse if the library is used in proxy or authentication contexts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107230. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart