PT-2026-107711 · Unknown · Async Http Client

CVE-2026-107282

·

Published

2026-10-07

·

Updated

2026-10-08

CVSS v4.0

9.4

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions AsyncHttpClient versions prior to 3.0.13 AsyncHttpClient versions prior to 2.16.1
Description Cross-host request replay occurs when the current request is updated but the target request and related proxy context continue to point to the original origin. This can lead to the transmission of the original host's path, Host header, Authorization credentials, or plaintext requests to the replay destination during connection-pool selection, CONNECT handling, realm selection, and TLS setup. This behavior can be triggered by documented ResponseFilter failover and retry paths.
Recommendations Update to version 3.0.13 or later. Update to version 2.16.1 or later.

Exploit

Fix

Insufficiently Protected Credentials

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107282
GHSA-JMQQ-X5G9-9P2W

Affected Products

Async Http Client