AsyncHttpClient (AHC) 库允许 Java 应用程序轻松执行 HTTP 请求,并异步处理 HTTP 响应。在 3.0.13 和 2.16.1 版本之前,Realm.Builder 会将不产生有效 nonce 的 Digest 挑战误认为 Basic 挑战。恶意源站或代理服务器可以在将挑战标记为 Digest 类型时省略 nonce 字段或将其置为空,从而导致客户端以可逆的 Basic 认证方式重新发送用户名和密码。源站和代理服务器端的挑战解析器均受此问题影响。该问题已在版本 3.0.13 和 2.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AsyncHttpClient | async-http-client | >= 3.0.0.Beta1, < 3.0.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107282 | 9.4 CRITICAL | AsyncHttpClient: Replay to a different host sends the original host request and credential |
| CVE-2026-107279 | 8.8 HIGH | AsyncHttpClient: Digest mutual authentication is switched off by a peer offering qop=auth- |
| CVE-2026-107281 | 7.6 HIGH | AsyncHttpClient: Connection pool key omits the authenticated principal, so an NTLM or Nego |
| CVE-2026-107227 | 7.5 HIGH | AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompress |
| CVE-2026-107232 | 7.5 HIGH | AsyncHttpClient: Origin credentials sent in cleartext to a proxy that rejects the CONNECT |
| CVE-2026-107230 | 7.4 HIGH | AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy l |
| CVE-2026-107280 | 6.9 MEDIUM | AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so |
| CVE-2026-107228 | 6.8 MEDIUM | AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHead |
| CVE-2026-107285 | 5.9 MEDIUM | AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunn |
| CVE-2026-107229 | 4.0 MEDIUM | AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossing |
| CVE-2026-107284 | 3.7 LOW | AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-Accept check |
| CVE-2026-107283 | 3.7 LOW | AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random so |
No comments yet