CVE-2026-107281
Received Received - Intake

NTLM Authentication Spoofing in AsyncHttpClient

Vulnerability report for CVE-2026-107281, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key excludes the authenticated principal for connection-oriented NTLM and Negotiate authentication. A pooled socket authenticated for one request can be reused by a request carrying another principal, and the server executes that later request as the first identity. Basic and Digest are not affected because they authenticate each request. This issue is fixed in versions 3.0.13 and 2.16.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
AsyncHttpClient async-http-client >= 3.0.0, < 3.0.13
AsyncHttpClient async-http-client >= 2.0.0, < 2.16.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The AsyncHttpClient (AHC) library before versions 3.0.13 and 2.16.1 has a flaw in its HTTP/1.1 connection-pool key. For NTLM and Negotiate authentication, the pool key does not include the authenticated principal. This allows a reused socket from one request to be used by another request with a different principal, causing the server to execute the later request under the first identity's permissions.

Detection Guidance

This vulnerability affects AsyncHttpClient versions prior to 3.0.13 and 2.16.1. To detect it, check the installed version of AsyncHttpClient in your Java application. If using Maven, run: mvn dependency:tree | grep async-http-client. If the version is below 3.0.13 or 2.16.1, the system is vulnerable.

Impact Analysis

An attacker could exploit this to impersonate another user's identity on the server by reusing a pooled connection. This could lead to unauthorized access to sensitive data or actions, depending on the permissions of the impersonated principal. The impact depends on the application's use of NTLM or Negotiate authentication.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating confidentiality requirements in GDPR and HIPAA. Non-compliance may result in legal penalties, data breach notifications, and reputational damage. Organizations using affected versions must update to mitigate risks.

Mitigation Strategies

Upgrade AsyncHttpClient to version 3.0.13 or 2.16.1 or later to address the connection-pool key issue with NTLM and Negotiate authentication.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107281. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart