Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107230— AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins

Quick assessment

Affected
AsyncHttpClient async-http-client
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

AsyncHttpClient(AHC)库允许 Java 应用程序轻松执行 HTTP 请求并异步处理 HTTP 响应。从版本 2.0.0 到 3.0.14,连接池分区在 Kerberos、SPNEGO、NTLM 以及经过身份验证的代理连接中,仍然缺少用于标识身份的字段。因此,未配置主体的登录、代理 realm、共享用户名的身份,以及 SOCKS 或 CONNECT 代理登录可能会复用以前以不同身份进行身份验证的 socket。这样,后续请求将以前一个身份执行,并可能导致该身份的数据或权限被其他调用者访问。在受影响的

CVSS 7.4 · High

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107230

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins
Source: CVE Program / CVE List V5
Vulnerability Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections. Logins without a configured principal, proxy realms, identities sharing a user name, and SOCKS or CONNECT proxy logins can reuse a socket authenticated as a different identity. A later request is then executed under the first identity and can expose that identity's data or authority to another caller. In the affected execution path, SpnegoEngine, NTLM, Kerberos, SPNEGO, SOCKS, and CONNECT control or expose the vulnerable behavior. This issue is fixed in version 3.0.14.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
源验证错误
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
AsyncHttpClient async-http-client >= 3.0.0, < 3.0.14 -

II. Public POCs for CVE-2026-107230

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107230

请登录查看更多情报信息。

Other References for CVE-2026-107230 (3)

Same Patch Batch · AsyncHttpClient · 2026-10-07 · 13 CVEs total

CVE-2026-107282 9.4 CRITICAL AsyncHttpClient: Replay to a different host sends the original host request and credential
CVE-2026-107279 8.8 HIGH AsyncHttpClient: Digest mutual authentication is switched off by a peer offering qop=auth-
CVE-2026-107231 8.7 HIGH AsyncHttpClient: Digest challenge without a usable nonce downgrades to Basic and sends the
CVE-2026-107281 7.6 HIGH AsyncHttpClient: Connection pool key omits the authenticated principal, so an NTLM or Nego
CVE-2026-107227 7.5 HIGH AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompress
CVE-2026-107232 7.5 HIGH AsyncHttpClient: Origin credentials sent in cleartext to a proxy that rejects the CONNECT
CVE-2026-107280 6.9 MEDIUM AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so
CVE-2026-107228 6.8 MEDIUM AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHead
CVE-2026-107285 5.9 MEDIUM AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunn
CVE-2026-107229 4.0 MEDIUM AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossing
CVE-2026-107284 3.7 LOW AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-Accept check
CVE-2026-107283 3.7 LOW AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random so

IV. Related Vulnerabilities

V. Comments for CVE-2026-107230

No comments yet


Leave a comment