Impact
AsyncHttpClient performs an HTTP to WebSocket upgrade. If the server returns a missing or invalid Sec‑WebSocket‑Accept header, the library aborts the handshake but continues installing the pipeline and invoking the onOpen callback. Frames that arrive in conjunction with the erroneous 101 response are still decoded and passed to application even though the handshake is considered a failure and the channel is closed shortly thereafter. This flaw allows a server to supply controlled WebSocket frames to a client library without completing the required authentication check, effectively bypassing the handshake validation step. The weakness is consistent with CWE‑345 (Incorrect Processing of Security‑relevant Information) and CWE‑670 (Incorrect Validation of Server Authenticator). The exposed data are the frames the attacker sends, and the integrity of the application flow is compromised because an application may believe a valid handshake occurred. The impact is data or logic exposure within the Java application context.
Affected Systems
AsyncHttpClient, the open‑source HTTP client used by many Java applications, is vulnerable in any pre‑3.0.12 and pre‑2.16.1 releases. The issue is present in both the 2.x and 3.x branches before the corresponding patch releases. Any Java project that imports AsyncHttpClient, enables WebSocket support, and communicates with an external WebSocket endpoint is potentially affected. The vulnerability does not depend on a particular operating system or runtime other than a Java environment that includes the library.
Risk and Exploitability
The CVSS score of 3.7 categorizes the flaw as low severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. The likely attack vector is remote, where an attacker controls a target server or lies in proximity to the client, sends a malicious upgrade response with an invalid Sec‑WebSocket‑Accept header, and injects arbitrary frames. Because the library still delivers frames after handshake failure, an attacker can send data or trigger logic that was intended only for valid connections. While the exploitation requires the client to accept the server's handshake request, the technical barrier is minimal once the client is listening; thus the risk remains present until the library is upgraded.
OpenCVE Enrichment