The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections. Logins without a configured principal, proxy realms, identities sharing a user name, and SOCKS or CONNECT proxy logins can reuse a socket authenticated as a different identity. A later request is then executed under the first identity and can expose that identity's data or authority to another caller. In the affected execution path, SpnegoEngine, NTLM, Kerberos, SPNEGO, SOCKS, and CONNECT control or expose the vulnerable behavior. This issue is fixed in version 3.0.14.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-346",
"CWE-863"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107230.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107230.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "207829264977095292499601748116713673981",
"length": 143
},
"id": "CVE-2026-107230-00fd1f47",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/PrincipalScopedPartitionKey.java",
"function": "hashCode"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "153916996126071209272523887429935450591",
"length": 120
},
"id": "CVE-2026-107230-05ee266f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/PrincipalScopedPartitionKey.java",
"function": "authenticatesTheConnection"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "216337645455228504456442236085620334944",
"length": 441
},
"id": "CVE-2026-107230-08dd8be2",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/AsyncHttpClientHandler.java",
"function": "finishUpdate"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "331833897347090815971013084865042896385",
"length": 319
},
"id": "CVE-2026-107230-0a0640c1",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/PrincipalScopedPartitionKey.java",
"function": "equals"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "188662664195786640372028479236414978673",
"length": 702
},
"id": "CVE-2026-107230-15f07d12",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java",
"function": "drainChannelAndExecuteNextRequest"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"93433090674291660602721226892375089617",
"124871769336575260286999810045509738530",
"116486042060170491646066986823511289458",
"56879699175863723265487252753518362275",
"21985406770973720082948224769836620899",
"91362782860887862533169374846502198182",
"65106963604868372344210889168730825288",
"20987544047064448532617563299535659209",
"24097941466687170895595074840306577122",
"194680379904939339011739582730810642595",
"327125621574217121790182384603642344919",
"335965001001229914547098986249210109768",
"248436753294692153175834958185111160137",
"25062331249109993063313376480148079055",
"126373262851361074253035887629419700220",
"195593505114399570954169939075025906116",
"240202648117076087255750287320830907376",
"639918062914562153325671701627733368",
"291874597913097938405009659509494034606",
"140624251166127262948366144519437700573",
"235369353386051401423220159159201900982",
"232770953902353601108085996130880581565",
"172780108101327824328598530317803018556",
"223571951632464239073886511390998399027",
"141670312626069673022712026508804479799",
"120720829874571589837815479803486940087",
"223005590513038700843275059081568784621",
"208399065712893106820947277197077547304",
"230405862360813878616651014959304473662",
"311051387487497187787815796146661366643",
"128050075736981122494684519133146176905",
"292581194076114169772740294679293191177"
],
"threshold": 0.9
},
"id": "CVE-2026-107230-47a606b9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "126566272227334157893807585929252866523",
"length": 138
},
"id": "CVE-2026-107230-4b43db38",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/PrincipalScopedPartitionKey.java",
"function": "toString"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"324640711923229571705157001076501434396",
"102135534485285245502282177742912940655",
"101057844397615265366839865088403166488",
"293648769464741952842202302083468462189"
],
"threshold": 0.9
},
"id": "CVE-2026-107230-4cf8fb3e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/ConnectSuccessInterceptor.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "236571269199409142999986107002309354986",
"length": 505
},
"id": "CVE-2026-107230-556ca332",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java",
"function": "call"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "186006243356908332271690944080993043533",
"length": 649
},
"id": "CVE-2026-107230-567ef220",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/test/java/org/asynchttpclient/netty/channel/ConnectionOrientedAuthHttp2Test.java",
"function": "anAuthenticatedProxyHopAlsoMakesTheConnectionUnshareable"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "228224712019150259287373469440899727795",
"length": 860
},
"id": "CVE-2026-107230-6aeedb83",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java",
"function": "reuseOrDeferHttp2Connection"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "305280811629889631101229902592176569203",
"length": 4943
},
"id": "CVE-2026-107230-6c5ab17b",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/NettyConnectListener.java",
"function": "onSuccess"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "99262104410909288036704228539031522216",
"length": 178
},
"id": "CVE-2026-107230-727a25ad",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java",
"function": "pooledProxyIdentity"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "190350274941263175260148343291906403417",
"length": 4046
},
"id": "CVE-2026-107230-93eadbf0",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java",
"function": "exitAfterHandlingRedirect"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"230252218409937185374589329267987007167",
"259064234689291323030493157049661638948",
"318482999250301388503544879850609554749",
"157496065143028108376909739255168836884",
"339062407646866997508487077663663034342"
],
"threshold": 0.9
},
"id": "CVE-2026-107230-9686c0c2",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"198347538168693771104943468879911234871",
"88693974438047429477965528402064938929",
"263854310283757804385229200870907088312",
"273728276846251189138463851227740694586",
"183246184726048006055685226422067927084",
"324916657790275864417020425889302448604",
"194938576279067618092982072537096593436",
"258338883993550807229381085434501285927",
"229229447403486222623702105488230113447",
"85723076190786244591897081822593415963",
"215188374530584553037784788961506747038",
"267325970249563956501386502882812083138",
"161670689812433265227374321908103736865",
"267438121420190078840248942571693475729"
],
"threshold": 0.9
},
"id": "CVE-2026-107230-9a30943a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/test/java/org/asynchttpclient/netty/channel/PrincipalScopedPartitionKeyTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "219855400109732602981156097590521582238",
"length": 761
},
"id": "CVE-2026-107230-9a37900f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/spnego/SpnegoEngine.java",
"function": "instance"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "259920600648405597617719739944920123144",
"length": 1070
},
"id": "CVE-2026-107230-9d523d8b",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/ConnectSuccessInterceptor.java",
"function": "exitAfterHandlingConnect"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "183166471604444123772075715405914209951",
"length": 1260
},
"id": "CVE-2026-107230-b03e1f1d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java",
"function": "replayRequest"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"212137420817513003272661127981763098873",
"61639241709888122195423560173532652169",
"206289568802560677073649803927275683561",
"156386976466162094536579409512419262233",
"47123441803726825413048598697267899900",
"96846548342962294774476296506058369737",
"251194134034562812221240731157317582788",
"293550375033013185961283698620373330862",
"177422182808681804555571936575724466625",
"109615330950546490701212997485846669270",
"100377008581943765613377472687150313028"
],
"threshold": 0.9
},
"id": "CVE-2026-107230-b5dcb69a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/test/java/org/asynchttpclient/netty/channel/ConnectionOrientedAuthHttp2Test.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"127986618409956445226427828999090966186",
"174790851769204684511461653728308993681",
"250996409704656588697193310360378297186",
"32648967933748315671431822279739927844",
"83372841197353880840441772258259525033",
"246876243337025724845371153052522265911",
"17921161314316031027366924549750783269",
"278670332234891630163224978253923833703",
"257012398342180704822202166464322596108",
"117595997420742104375541616468167281190",
"95632161375166290609015208992806312913",
"211610128806506335440662469556408017008",
"173427574589771394876841159737421520656",
"237189629786498583649919531183990206906",
"295334467321061154790131695838011586200",
"157835046501659548765243809178558657459",
"167059683007245896055845962848053021937",
"80337846603732522253344724874917859412",
"31894184871209223071812418141922415244",
"30628510422740860012138056928215296195",
"219575933312850878213736531941037469901",
"258888431812763153128370930497843934613",
"149099329713971916166309439781157993809",
"247138092853448795338564758854571453690",
"130897842157103327018956025655949810683",
"33545848544978846710999123923637380434",
"208847637667456973250604598745748001765",
"220469441637654683207300693714702131259",
"169000223524695629064077326128903873618",
"2526517579523459158001464242429540947",
"214379367726140002768007950129316420569",
"108917011382339282198381359584952714541",
"206872482133483721318259484673765416326",
"133586937405521296148031577534788431091",
"288404506477392706060811720297747860636"
],
"threshold": 0.9
},
"id": "CVE-2026-107230-bb51b5ff",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/PrincipalScopedPartitionKey.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"216658882485047940377808220103719164077",
"291410308353039075159611847985024754971",
"208953207360956710581290323390157574051",
"328830875777361420655462295279614911682",
"275850978915127589061194349045211436009",
"76552119336288341962929911687445431456",
"336933403770378274265800302179416602148",
"288297801498426531823106120706135940808",
"288905765685998110598824758637203846743",
"244707342180699396265258913696468599427",
"98291243741720524820785205544664741775",
"268430873358171231343735668012635604275",
"140540738789416079381522355062644051345",
"185040968695725624137957272203547712114",
"311710575253368585032805599539430336957",
"266037891690263218224017173168140497905",
"121352377566292958190909581860023986796"
],
"threshold": 0.9
},
"id": "CVE-2026-107230-bc9b3e2b",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/NettyConnectListener.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "274056838268517788336078687702575302798",
"length": 189
},
"id": "CVE-2026-107230-c56d4653",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java",
"function": "drainChannelAndOffer"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "235448841304189038940603464319444951681",
"length": 237
},
"id": "CVE-2026-107230-ca328d68",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/PrincipalScopedPartitionKey.java",
"function": "scope"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"117826522990948645694523771117591632405",
"228870753667427262978224835216334296807",
"319660676515468141380068812565945647146",
"77584563705038215834821165360008549785",
"253748667605701975745147212023993879095"
],
"threshold": 0.9
},
"id": "CVE-2026-107230-d0d916f6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "34186803755513795609731285716566881112",
"length": 263
},
"id": "CVE-2026-107230-d748b633",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/test/java/org/asynchttpclient/netty/channel/PrincipalScopedPartitionKeyTest.java",
"function": "noRealmAndNoPrincipalAreLeftAlone"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "237658669388428581168292506659585701793",
"length": 1709
},
"id": "CVE-2026-107230-e15139aa",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java",
"function": "pollPooledChannel"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"316005369843953868188089167211930995905",
"150676018855369799234781518236135247503",
"59935449236067841765842089712501404680",
"77651570202336003750837814292472466121",
"315080205631177328547300542342914186394"
],
"threshold": 0.9
},
"id": "CVE-2026-107230-ecf085f1",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/AsyncHttpClientHandler.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "83938093609135223227945608707585661795",
"length": 591
},
"id": "CVE-2026-107230-f1f0ccda",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/NettyConnectListener.java",
"function": "registerHttp2AndManageSemaphore"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"199799369471290046493771550018187999602",
"64477786206459186320602016952280231864",
"98328852202835407003001980484485874818",
"285994509004746486345266926353231648025",
"38107847211425442749522819298076352333",
"333830329601045603418308124917612548536",
"188768243612036959006106864226593316960",
"123228821245438047370808461759038789808",
"123700776458424233100732464298967602922",
"2098433556046745845392034248628971546",
"55354597047424166451728065700028502841",
"166072350818161522239305931128767613402",
"35330945837709095014620414672878803003",
"21433143540884350705602467070368767144",
"65632174101029166030131249900859822685",
"258250617351459046149563116527603391517",
"62704955537420645831352655350244173095",
"329769931327776870489772139851878081842",
"233633742307558377248387184572356132365",
"44903121700923941870132625493890776119",
"203654498032212023137982778641672340633",
"265557039982203286620414448348757207118",
"297984591897954330233220296647237841180",
"16199471775827083655709932964930365416",
"252019773874908522501195209350316339045",
"231946789511940127972577088736891120451",
"18792534142087041502043293332132335718",
"309833688576198317349212301033004304617",
"315877443561401917827878224540255579986",
"115016809107907343413678226866080978200",
"49485397442860934635647072286592938561",
"198103053977475087979008353129494289378",
"247229172440573046437682230828766176485",
"78435453165563865196821265806420580742",
"221917283024851916640136890805661378666",
"240069271488636792314513340154549848773",
"305485067885271206490528297331219906364",
"334802417743515443338498682948514342341",
"163470140379919608593849803273146765614",
"183197181482800396646740426557858113729",
"59901532009057188027767731161860428055",
"182243794964009227352096281305679722614",
"190791379955770719900500798642814477625",
"252966926127625432791389067910761388970"
],
"threshold": 0.9
},
"id": "CVE-2026-107230-f452cc21",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054",
"target": {
"file": "client/src/main/java/org/asynchttpclient/spnego/SpnegoEngine.java"
}
}
]
"2026-10-09T07:06:48Z"