Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, WebSocketHandler.upgrade aborts a handshake whose Sec-WebSocket-Accept value is missing or invalid but continues into pipeline installation and onOpen delivery. Frames coalesced with the invalid 101 response can be decoded and delivered from a peer that did not prove the handshake, although the request future fails and the channel closes. This issue is fixed in versions 3.0.12 and 2.16.1.
Published: 2026-10-07
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure & Unauthorized Interaction
Action: Patch
AI Analysis

Impact

AsyncHttpClient performs an HTTP to WebSocket upgrade. If the server returns a missing or invalid Sec‑WebSocket‑Accept header, the library aborts the handshake but continues installing the pipeline and invoking the onOpen callback. Frames that arrive in conjunction with the erroneous 101 response are still decoded and passed to application even though the handshake is considered a failure and the channel is closed shortly thereafter. This flaw allows a server to supply controlled WebSocket frames to a client library without completing the required authentication check, effectively bypassing the handshake validation step. The weakness is consistent with CWE‑345 (Incorrect Processing of Security‑relevant Information) and CWE‑670 (Incorrect Validation of Server Authenticator). The exposed data are the frames the attacker sends, and the integrity of the application flow is compromised because an application may believe a valid handshake occurred. The impact is data or logic exposure within the Java application context.

Affected Systems

AsyncHttpClient, the open‑source HTTP client used by many Java applications, is vulnerable in any pre‑3.0.12 and pre‑2.16.1 releases. The issue is present in both the 2.x and 3.x branches before the corresponding patch releases. Any Java project that imports AsyncHttpClient, enables WebSocket support, and communicates with an external WebSocket endpoint is potentially affected. The vulnerability does not depend on a particular operating system or runtime other than a Java environment that includes the library.

Risk and Exploitability

The CVSS score of 3.7 categorizes the flaw as low severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. The likely attack vector is remote, where an attacker controls a target server or lies in proximity to the client, sends a malicious upgrade response with an invalid Sec‑WebSocket‑Accept header, and injects arbitrary frames. Because the library still delivers frames after handshake failure, an attacker can send data or trigger logic that was intended only for valid connections. While the exploitation requires the client to accept the server's handshake request, the technical barrier is minimal once the client is listening; thus the risk remains present until the library is upgraded.

Generated by OpenCVE AI on October 7, 2026 at 22:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AsyncHttpClient to version 3.0.12 or 2.16.1 or later, which include the fix that properly rejects handshakes with invalid Sec‑WebSocket‑Accept headers before pipeline installation.
  • If an upgrade is not immediately feasible, modify your code to enforce strict handshake validation: verify the Sec‑WebSocket‑Accept header and abort the connection before adding any handlers or invoking callbacks if the header is missing or incorrect.
  • Add monitoring or logging for anomalous WebSocket frames or handshake failures that occur after a 101 response to detect potential manipulation, and consider disabling WebSocket usage for non‑essential services until the library is updated.

Generated by OpenCVE AI on October 7, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, WebSocketHandler.upgrade aborts a handshake whose Sec-WebSocket-Accept value is missing or invalid but continues into pipeline installation and onOpen delivery. Frames coalesced with the invalid 101 response can be decoded and delivered from a peer that did not prove the handshake, although the request future fails and the channel closes. This issue is fixed in versions 3.0.12 and 2.16.1.
Title AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-Accept check
Weaknesses CWE-345
CWE-670
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T14:54:57.517Z

Reserved: 2026-10-07T15:53:23.586Z

Link: CVE-2026-107284

cve-icon Vulnrichment

Updated: 2026-10-08T14:53:27.302Z

cve-icon NVD

Status : Received

Published: 2026-10-07T22:17:04.483

Modified: 2026-10-08T15:17:40.553

Link: CVE-2026-107284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:00:15Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-670

    Always-Incorrect Control Flow Implementation