AsyncHttpClient (AHC) 库允许 Java 应用程序轻松执行 HTTP 请求并异步处理 HTTP 响应。在版本 3.0.12 和 2.16.1 之前,通过代理进行的 WebSocket 请求使用 CONNECT 方法隧道传输,但 和 仅根据 URI 是否为安全协议(如 HTTPS)来决定是否附加代理认证信息和绝对形式的目标地址。由于 WebSocket 协议未被标记为安全协议,因此隧道传输中发送给原始服务器的 WebSocket 升级请求中会包含代理的 头部值。这会导致基本认证(Basic)凭据可
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AsyncHttpClient | async-http-client | >= 3.0.0, <3.0.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107282 | 9.4 CRITICAL | AsyncHttpClient: Replay to a different host sends the original host request and credential |
| CVE-2026-107279 | 8.8 HIGH | AsyncHttpClient: Digest mutual authentication is switched off by a peer offering qop=auth- |
| CVE-2026-107231 | 8.7 HIGH | AsyncHttpClient: Digest challenge without a usable nonce downgrades to Basic and sends the |
| CVE-2026-107281 | 7.6 HIGH | AsyncHttpClient: Connection pool key omits the authenticated principal, so an NTLM or Nego |
| CVE-2026-107227 | 7.5 HIGH | AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompress |
| CVE-2026-107232 | 7.5 HIGH | AsyncHttpClient: Origin credentials sent in cleartext to a proxy that rejects the CONNECT |
| CVE-2026-107230 | 7.4 HIGH | AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy l |
| CVE-2026-107280 | 6.9 MEDIUM | AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so |
| CVE-2026-107228 | 6.8 MEDIUM | AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHead |
| CVE-2026-107229 | 4.0 MEDIUM | AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossing |
| CVE-2026-107284 | 3.7 LOW | AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-Accept check |
| CVE-2026-107283 | 3.7 LOW | AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random so |
No comments yet