Disclosure summary
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, cross-host request replay updates the current request but leaves the target request and related proxy context pointing at the original origin. Connection-pool selection, CONNECT handling, realm selection, and TLS setup can consequently send the original host's path, Host header, Authorization credentials, or plaintext request to the replay destination. Documented ResponseFilter failover and retry paths can trigger the replay. This issue is fixed in versions 3.0.13 and 2.16.1.
Source-reported weakness categories
CWE-319, CWE-441, CWE-522
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107282
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-jmqq-x5g9-9p2w
Open original source · Updated Oct 08, 2026
AsyncHttpClient: Replay to a different host sends the original host request and credentials to the new host
Source severity: CRITICAL / 9.4
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| maven | org.asynchttpclient:async-http-client | >= 3.0.0, | 3.0.13 |
| maven | org.asynchttpclient:async-http-client | >= 2.0.0, | 2.16.1 |
Original records & references
PUBLISHED 2026-10-07T18:17:04-04:00
MODIFIED 2026-10-09T23:17:06-04:00
INGESTED 2026-10-10T20:55:02-04:00