AsyncHttpClient(AHC)库允许 Java 应用程序轻松执行 HTTP 请求并异步处理 HTTP 响应。在版本 3.0.12 中,如果对端仅提供 Digest 挑战中的 qop=auth-int,则会导致相互身份验证验证被跳过。由于 AuthenticatorUtils.computeExpectedRspAuth 方法对 auth-int 返回的期望值为空,Interceptors 将该结果视为“不可验证但非致命”,从而接受带有无效 rspauth 值的响应。因此,即使对端不知道共享密钥,也可能被误
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AsyncHttpClient | async-http-client | = 3.0.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107282 | 9.4 CRITICAL | AsyncHttpClient: Replay to a different host sends the original host request and credential |
| CVE-2026-107231 | 8.7 HIGH | AsyncHttpClient: Digest challenge without a usable nonce downgrades to Basic and sends the |
| CVE-2026-107281 | 7.6 HIGH | AsyncHttpClient: Connection pool key omits the authenticated principal, so an NTLM or Nego |
| CVE-2026-107227 | 7.5 HIGH | AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompress |
| CVE-2026-107232 | 7.5 HIGH | AsyncHttpClient: Origin credentials sent in cleartext to a proxy that rejects the CONNECT |
| CVE-2026-107230 | 7.4 HIGH | AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy l |
| CVE-2026-107280 | 6.9 MEDIUM | AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so |
| CVE-2026-107228 | 6.8 MEDIUM | AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHead |
| CVE-2026-107285 | 5.9 MEDIUM | AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunn |
| CVE-2026-107229 | 4.0 MEDIUM | AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossing |
| CVE-2026-107284 | 3.7 LOW | AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-Accept check |
| CVE-2026-107283 | 3.7 LOW | AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random so |
No comments yet