AsyncHttpClient(AHC)库允许 Java 应用程序轻松执行 HTTP 请求并异步处理 HTTP 响应。在 3.x 版本的 3.0.12 之前以及 2.x 版本的 2.16.1 之前,客户端会依据最后一次请求的方法来推断是否存在 HTTP 代理隧道,而非根据 CONNECT 请求的实际结果进行判断。在代理拒绝 CONNECT 请求后,重定向或身份验证处理器可能将原始请求及其 Authorization 凭据写入仍处于明文状态的代理连接中。攻击者可以直接获取 Basic 身份验证凭据,并可能对 NTLM
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AsyncHttpClient | async-http-client | >= 3.0.0, < 3.0.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107282 | 9.4 CRITICAL | AsyncHttpClient: Replay to a different host sends the original host request and credential |
| CVE-2026-107279 | 8.8 HIGH | AsyncHttpClient: Digest mutual authentication is switched off by a peer offering qop=auth- |
| CVE-2026-107231 | 8.7 HIGH | AsyncHttpClient: Digest challenge without a usable nonce downgrades to Basic and sends the |
| CVE-2026-107281 | 7.6 HIGH | AsyncHttpClient: Connection pool key omits the authenticated principal, so an NTLM or Nego |
| CVE-2026-107227 | 7.5 HIGH | AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompress |
| CVE-2026-107230 | 7.4 HIGH | AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy l |
| CVE-2026-107280 | 6.9 MEDIUM | AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so |
| CVE-2026-107228 | 6.8 MEDIUM | AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHead |
| CVE-2026-107285 | 5.9 MEDIUM | AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunn |
| CVE-2026-107229 | 4.0 MEDIUM | AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossing |
| CVE-2026-107284 | 3.7 LOW | AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-Accept check |
| CVE-2026-107283 | 3.7 LOW | AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random so |
No comments yet