CVE-2026-107284
Received Received - Intake

WebSocket Handshake Bypass in AsyncHttpClient

Vulnerability report for CVE-2026-107284, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, WebSocketHandler.upgrade aborts a handshake whose Sec-WebSocket-Accept value is missing or invalid but continues into pipeline installation and onOpen delivery. Frames coalesced with the invalid 101 response can be decoded and delivered from a peer that did not prove the handshake, although the request future fails and the channel closes. This issue is fixed in versions 3.0.12 and 2.16.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
AsyncHttpClient async-http-client >= 3.0.0, < 3.0.12
AsyncHttpClient async-http-client >= 2.0.0, < 2.16.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-670 The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The AsyncHttpClient (AHC) library before versions 3.0.12 and 2.16.1 has a flaw in WebSocket handshake handling. When a WebSocket upgrade request receives an invalid or missing Sec-WebSocket-Accept header, the library incorrectly proceeds to install a pipeline and trigger the onOpen event. This allows frames combined with the invalid 101 response to be decoded and delivered from an unauthenticated peer, even though the handshake technically fails and the channel closes.

Detection Guidance

This vulnerability affects AsyncHttpClient versions before 3.0.12 and 2.16.1. To detect it, check the installed version of the library in your Java application dependencies. If using Maven, run: mvn dependency:tree | grep async-http-client. If the version is below 3.0.12 or 2.16.1, the system is vulnerable.

Impact Analysis

An attacker could exploit this to send malicious WebSocket frames to your application without completing a proper handshake. This might lead to unintended data processing or actions based on unauthenticated input, potentially causing incorrect behavior or exposing sensitive information if the application processes the malformed frames.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized data processing or exposure if malicious frames are processed. For GDPR, it may violate principles of data integrity and confidentiality. For HIPAA, it could risk unauthorized access to protected health information if exploited in a healthcare context.

Mitigation Strategies

Upgrade AsyncHttpClient to version 3.0.12 or later, or 2.16.1 or later if using the 2.x branch. This addresses the WebSocket handshake validation issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107284. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart