Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections. Logins without a configured principal, proxy realms, identities sharing a user name, and SOCKS or CONNECT proxy logins can reuse a socket authenticated as a different identity. A later request is then executed under the first identity and can expose that identity's data or authority to another caller. In the affected execution path, SpnegoEngine, NTLM, Kerberos, SPNEGO, SOCKS, and CONNECT control or expose the vulnerable behavior. This issue is fixed in version 3.0.14.
Published: 2026-10-07
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: Information Disclosure via Credential Misuse
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in the AsyncHttpClient library permits a request that authenticates using Kerberos, SPNEGO, NTLM, or a proxy to reuse a previously established socket that may have been authenticated as a different identity. Because the connection pool ignores fields that identify the identity, an attacker can request a connection that has already been authenticated as another user. The subsequent HTTPS request is then executed under the mistaken identity, potentially exposing data or authority belonging to the original user. This flaw maps to CWE-346 (Broken Access Control) and CWE-863 (Improper Inter-process Communication) and results in unauthorized data access rather than arbitrary code execution.

Affected Systems

Vendors affected are those who integrate the AsyncHttpClient library version 2.0.0 through 3.0.14. Applications built in Java that rely on this library for HTTP, SPNEGO, NTLM, or proxy authentication are impacted. No specific third‑party products are named; the issue affects any Java application linking to AsyncHttpClient within the stated version range.

Risk and Exploitability

The CVSS score of 7.4 indicates a high severity with moderate impact on confidentiality. The EPSS score is currently not available, so the exploitation probability is unknown, and the vulnerability is not listed in CISA’s KEV catalog. Attackers with the ability to introduce or modify the code executed by the affected Java application can trigger the condition; thus the vector is likely local or remote within the application context. No formal exploitation chain is documented, but the flaw allows legitimate requests to be served under a different identity, enabling data leakage or privilege expansion.

Generated by OpenCVE AI on October 7, 2026 at 22:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AsyncHttpClient to version 3.0.14 or later, where the connection pool properly partitions connections by identity.
  • If upgrading immediately is not possible, disable connection pooling for NTLM, SPNEGO, and proxy authentication flows until the patch is applied.
  • Review and constrict any application logic that may re‑use connections without ensuring correct authentication, and implement additional runtime checks to confirm identity before processing.

Generated by OpenCVE AI on October 7, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections. Logins without a configured principal, proxy realms, identities sharing a user name, and SOCKS or CONNECT proxy logins can reuse a socket authenticated as a different identity. A later request is then executed under the first identity and can expose that identity's data or authority to another caller. In the affected execution path, SpnegoEngine, NTLM, Kerberos, SPNEGO, SOCKS, and CONNECT control or expose the vulnerable behavior. This issue is fixed in version 3.0.14.
Title AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins
Weaknesses CWE-346
CWE-863
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T21:00:47.997Z

Reserved: 2026-10-07T14:34:14.817Z

Link: CVE-2026-107230

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T22:17:03.133

Modified: 2026-10-07T22:17:03.133

Link: CVE-2026-107230

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T22:45:17Z

Weaknesses