AsyncHttpClient(AHC)库允许 Java 应用程序轻松执行 HTTP 请求并异步处理 HTTP 响应。从版本 2.1.0 到 3.0.14,默认启用的 Cookie 存储在源域存在任何已存储 Cookie 时,会替换通过 或 显式提供的 Cookie 头字段。在共享客户端中,来自一个用户的已存储 Cookie 可能会替换另一个用户的请求 Cookie,从而导致请求在错误的会话上下文中执行。此问题绕过了早期针对 CVE-2024-53990 的修复措施,该修复仅覆盖通过 方法提供的 Cookie,而未
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AsyncHttpClient | async-http-client | >= 3.0.0, < 3.0.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107282 | 9.4 CRITICAL | AsyncHttpClient: Replay to a different host sends the original host request and credential |
| CVE-2026-107279 | 8.8 HIGH | AsyncHttpClient: Digest mutual authentication is switched off by a peer offering qop=auth- |
| CVE-2026-107231 | 8.7 HIGH | AsyncHttpClient: Digest challenge without a usable nonce downgrades to Basic and sends the |
| CVE-2026-107281 | 7.6 HIGH | AsyncHttpClient: Connection pool key omits the authenticated principal, so an NTLM or Nego |
| CVE-2026-107227 | 7.5 HIGH | AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompress |
| CVE-2026-107232 | 7.5 HIGH | AsyncHttpClient: Origin credentials sent in cleartext to a proxy that rejects the CONNECT |
| CVE-2026-107230 | 7.4 HIGH | AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy l |
| CVE-2026-107280 | 6.9 MEDIUM | AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so |
| CVE-2026-107285 | 5.9 MEDIUM | AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunn |
| CVE-2026-107229 | 4.0 MEDIUM | AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossing |
| CVE-2026-107284 | 3.7 LOW | AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-Accept check |
| CVE-2026-107283 | 3.7 LOW | AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random so |
No comments yet