Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key excludes the authenticated principal for connection-oriented NTLM and Negotiate authentication. A pooled socket authenticated for one request can be reused by a request carrying another principal, and the server executes that later request as the first identity. Basic and Digest are not affected because they authenticate each request. This issue is fixed in versions 3.0.13 and 2.16.1.
Published: 2026-10-07
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Impersonation/Authorization Bypass
Action: Immediate Patch
AI Analysis

Impact

The AsyncHttpClient library creates a connection-pool key based on request parameters but omits the authenticated principal for NTLM and Negotiate authentication, allowing a socket authenticated for one identity to be reused for requests using a different principal and causing the server to execute those subsequent requests as the original identity. This flaw can lead to unauthorized access or actions performed with higher privileges.

Affected Systems

Any Java application that uses AsyncHttpClient versions earlier than 3.0.13 or 2.16.1 and relies on NTLM or Negotiate authentication is vulnerable. Basic or Digest authentication is not affected. Versions 3.0.13 and 2.16.1, and later releases, contain a fix.

Risk and Exploitability

The vulnerability presents a moderate to high risk with a CVSS score of 7.6. Exploitation requires an attacker to influence a client application using the affected library so that it initiates requests under multiple identities. No EPSS data is available, and the flaw is not listed in the CISA KEV catalog, but the authentication bypass could be used to elevate privileges on a target system if the server trusts the authenticated identity. The likely attack vector is remote exploitation via the client application, and no public exploit is known.

Generated by OpenCVE AI on October 7, 2026 at 22:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AsyncHttpClient to version 3.0.13, 2.16.1, or later.
  • Configure the client or application to maintain separate connections per authenticated principal or disable NTLM/Negotiate reuse if possible.
  • Review and enforce server‑side access controls, ensuring that authenticated identities are properly validated against required permissions.
  • Monitor logs for authentication anomalies and consider applying network segmentation or application firewall rules to limit exposure.

Generated by OpenCVE AI on October 7, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key excludes the authenticated principal for connection-oriented NTLM and Negotiate authentication. A pooled socket authenticated for one request can be reused by a request carrying another principal, and the server executes that later request as the first identity. Basic and Digest are not affected because they authenticate each request. This issue is fixed in versions 3.0.13 and 2.16.1.
Title AsyncHttpClient: Connection pool key omits the authenticated principal, so an NTLM or Negotiate connection is reused across identities
Weaknesses CWE-346
CWE-863
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T17:58:10.542Z

Reserved: 2026-10-07T15:53:23.585Z

Link: CVE-2026-107281

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T22:17:03.980

Modified: 2026-10-08T18:17:15.907

Link: CVE-2026-107281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T22:45:17Z

Weaknesses