CVE-2026-107284 - AsyncHttpClient Vulnerability Discovered
CVE-2026-107284 - AsyncHttpClient Vulnerability 🚨
A new vulnerability, CVE-2026-107284, has been identified in the AsyncHttpClient (AHC) library, which allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Specifically, prior to versions 3.0.12 and 2.16.1, the WebSocketHandler.upgrade aborts a handshake whose Sec-WebSocket-Accept value is missing or invalid but continues into pipeline installation and onOpen delivery. This means that frames coalesced with the invalid 101 response can be decoded and delivered from a peer that did not prove the handshake, although the request future fails and the channel closes. This issue is fixed in versions 3.0.12 and 2.16.1.
The CVE-2026-107284 vulnerability has been assigned a CVSS V3.1 score of AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N, indicating a low integrity impact. It is also associated with Common Weakness Enumerations CWE-345 and CWE-670. The CVE was newly received on October 7, 2026. Regarding impact, the report indicates that no affected product has been recorded yet. A new affected value has been received, linking to the CVE on GitHub.
Vulnerability history details can be useful for understanding the evolution of a vulnerability and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. In this context, researchers are actively scanning GitHub repositories to detect new proof-of-concept exploits, monitoring for public exploits and proof-of-concepts that have been published on GitHub. The vulnerability’s progression is tracked through various references, including GitHub commits such as 75a278550aa9a980009d022fb4e635f9c8738c03 and ccdcaa627db6d96dcc42105212cb3ba5048bd7f9. Additionally, specific releases like async-http-client-project-2.16.1 and async-http-client-project-3.0.12 address the issue, and a security advisory GHSA-rwhr-j9rv-85f8 provides further information.
For more details, you can read the complete article here: Read full article