The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key excludes the authenticated principal for connection-oriented NTLM and Negotiate authentication. A pooled socket authenticated for one request can be reused by a request carrying another principal, and the server executes that later request as the first identity. Basic and Digest are not affected because they authenticate each request. This issue is fixed in versions 3.0.13 and 2.16.1.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-346",
"CWE-863"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107281.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107281.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "288730145480338461962172404755049731948",
"length": 327
},
"id": "CVE-2026-107281-0589ee7c",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/AsyncHttpClientHandler.java",
"function": "finishUpdate"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "51616862176537487450775212183040078711",
"length": 3160
},
"id": "CVE-2026-107281-15b37657",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java",
"function": "exitAfterHandlingRedirect"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"223012992018971433217073035018353617495",
"260928949143965625216228429390615520694",
"144933053861689910150682866581558024210",
"275610558554123132140596225591817034499",
"126925599087567496020378534943260354412",
"47050140889884445704261638847428305410",
"153890858470430959851797015456599118764",
"323210720716027054157334774983550825676"
],
"threshold": 0.9
},
"id": "CVE-2026-107281-1768647b",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"219246596221720898981563676126452787927",
"112413554918931264338179563940130289539",
"262908889413526511266896616639455764237"
],
"threshold": 0.9
},
"id": "CVE-2026-107281-26220b3f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f",
"target": {
"file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "278349082742419654169212630117273520780",
"length": 3240
},
"id": "CVE-2026-107281-2bad9088",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java",
"function": "exitAfterHandlingRedirect"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "20330549020912931133227266814408619469",
"length": 482
},
"id": "CVE-2026-107281-2c616334",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java",
"function": "pollPooledChannel"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"223012992018971433217073035018353617495",
"260928949143965625216228429390615520694",
"240544823618641810682492508157506598841",
"7449607784923438107087451227101050276",
"126925599087567496020378534943260354412",
"47050140889884445704261638847428305410",
"153890858470430959851797015456599118764",
"170534849440382169764625176003874828809"
],
"threshold": 0.9
},
"id": "CVE-2026-107281-33808d30",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "331132602917146773837631122170563207103",
"length": 939
},
"id": "CVE-2026-107281-3ed5bd6a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java",
"function": "replayRequest"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "89708691802783241181137648851968082998",
"length": 123
},
"id": "CVE-2026-107281-5be06b7d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java",
"function": "drainChannelAndOffer"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"327841583408810174882727307259366418457",
"225856860697427524412922987284257857697",
"51257216243098803863131068348992798560",
"228989682229619968745464014755724360540",
"319665170600263907654050432177095818664",
"113080282653837900945173783955297452512",
"336058670116607470849419202969332581285",
"160058220258090674048435543249555965928"
],
"threshold": 0.9
},
"id": "CVE-2026-107281-6c8f74b3",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/AsyncHttpClientHandler.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "288730145480338461962172404755049731948",
"length": 327
},
"id": "CVE-2026-107281-76dc2812",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/AsyncHttpClientHandler.java",
"function": "finishUpdate"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "89708691802783241181137648851968082998",
"length": 123
},
"id": "CVE-2026-107281-880b9f6c",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java",
"function": "drainChannelAndOffer"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"208038687406667484958729831464410022470",
"58309572727667912865549178078357225101",
"275740222303063859441307579401870662191",
"3706280016868164320978224880517816544",
"79311042076409514056309114404386819167",
"99135657026062383629714676693144318205",
"108722099215827632157783584217716810918",
"231592124670771851231841792592778580575",
"240608507889312564265508033419256884139",
"250803485582796011298073074569254702939",
"308876809136388913929276664471295871098",
"149393809071478709505946281990802958605",
"160645704852117574973522885100840227388",
"249172951662678749534536580337439913835",
"244631750887743614148967642982326203865",
"165215327185258329068577322101145385685",
"222567340153444217976560473832578952507",
"7250222536701251939383982077645943108",
"9068377061838886497670338903994837969"
],
"threshold": 0.9
},
"id": "CVE-2026-107281-a30d3273",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"327841583408810174882727307259366418457",
"225856860697427524412922987284257857697",
"51257216243098803863131068348992798560",
"228989682229619968745464014755724360540",
"319665170600263907654050432177095818664",
"113080282653837900945173783955297452512",
"336058670116607470849419202969332581285",
"160058220258090674048435543249555965928"
],
"threshold": 0.9
},
"id": "CVE-2026-107281-b0f0cfc3",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/AsyncHttpClientHandler.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "78898404868275482304696245035362744337",
"length": 1376
},
"id": "CVE-2026-107281-b774c831",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java",
"function": "pollPooledChannel"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"290083453370474412497177000962957828819",
"252993441232014134897406815816077590655",
"278504100699472608190267584753781311223",
"183637216311738231097493231616565295217",
"280623017119974790291096562373203240203",
"315845315827709108031466988960321070936",
"93187974517077857492175201020565040781",
"28930214874688961451802198363549372521",
"165215327185258329068577322101145385685",
"222567340153444217976560473832578952507",
"7250222536701251939383982077645943108",
"9068377061838886497670338903994837969"
],
"threshold": 0.9
},
"id": "CVE-2026-107281-c6927e24",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "319981061666573934872902157208912328509",
"length": 685
},
"id": "CVE-2026-107281-c7b286ac",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f",
"target": {
"file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java",
"function": "add"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "185973529296049735474105907057052587611",
"length": 1098
},
"id": "CVE-2026-107281-d785d397",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java",
"function": "replayRequest"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"227454738693993203136368648783413201493",
"173821234568441741612041921533159820472",
"186484411045948665807222152173473212150",
"224693335022652767092140525341883717127",
"339658646034294281944169177073152799128",
"174709020745150500971144237594942952841",
"117457524716875049023775804107575228539",
"98093989558677756028346503501459784145"
],
"threshold": 0.9
},
"id": "CVE-2026-107281-eaad4c77",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"339658646034294281944169177073152799128",
"174709020745150500971144237594942952841",
"117457524716875049023775804107575228539",
"98093989558677756028346503501459784145"
],
"threshold": 0.9
},
"id": "CVE-2026-107281-f9597278",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java"
}
}
]
"2026-10-09T07:06:52Z"