Impact
The vulnerability in the AsyncHttpClient library permits a request that authenticates using Kerberos, SPNEGO, NTLM, or a proxy to reuse a previously established socket that may have been authenticated as a different identity. Because the connection pool ignores fields that identify the identity, an attacker can request a connection that has already been authenticated as another user. The subsequent HTTPS request is then executed under the mistaken identity, potentially exposing data or authority belonging to the original user. This flaw maps to CWE-346 (Broken Access Control) and CWE-863 (Improper Inter-process Communication) and results in unauthorized data access rather than arbitrary code execution.
Affected Systems
Vendors affected are those who integrate the AsyncHttpClient library version 2.0.0 through 3.0.14. Applications built in Java that rely on this library for HTTP, SPNEGO, NTLM, or proxy authentication are impacted. No specific third‑party products are named; the issue affects any Java application linking to AsyncHttpClient within the stated version range.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity with moderate impact on confidentiality. The EPSS score is currently not available, so the exploitation probability is unknown, and the vulnerability is not listed in CISA’s KEV catalog. Attackers with the ability to introduce or modify the code executed by the affected Java application can trigger the condition; thus the vector is likely local or remote within the application context. No formal exploitation chain is documented, but the flaw allows legitimate requests to be served under a different identity, enabling data leakage or privilege expansion.
OpenCVE Enrichment