CVE-2026-107281

Source
https://cve.org/CVERecord?id=CVE-2026-107281
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107281.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107281
Aliases
  • GHSA-vvp4-63h8-v5pm
Downstream
Published
2026-10-07T21:19:09Z
Modified
2026-10-09T07:06:52Z
Severity
  • 7.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
AsyncHttpClient: Connection pool key omits the authenticated principal, so an NTLM or Negotiate connection is reused across identities
Details

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key excludes the authenticated principal for connection-oriented NTLM and Negotiate authentication. A pooled socket authenticated for one request can be reused by a request carrying another principal, and the server executes that later request as the first identity. Basic and Digest are not affected because they authenticate each request. This issue is fixed in versions 3.0.13 and 2.16.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-346",
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107281.json"
}
References

Affected packages

Git / github.com/asynchttpclient/async-http-client

Affected ranges

Type
GIT
Repo
https://github.com/asynchttpclient/async-http-client
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.0.13"
        },
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.16.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

async-http-client-project-2.*
async-http-client-project-2.0.0
async-http-client-project-2.0.1
async-http-client-project-2.0.10
async-http-client-project-2.0.11
async-http-client-project-2.0.12
async-http-client-project-2.0.13
async-http-client-project-2.0.14
async-http-client-project-2.0.15
async-http-client-project-2.0.16
async-http-client-project-2.0.17
async-http-client-project-2.0.18
async-http-client-project-2.0.19
async-http-client-project-2.0.2
async-http-client-project-2.0.20
async-http-client-project-2.0.21
async-http-client-project-2.0.22
async-http-client-project-2.0.23
async-http-client-project-2.0.24
async-http-client-project-2.0.3
async-http-client-project-2.0.4
async-http-client-project-2.0.5
async-http-client-project-2.0.6
async-http-client-project-2.0.7
async-http-client-project-2.0.8
async-http-client-project-2.0.9
async-http-client-project-2.1.0
async-http-client-project-2.1.0-RC1
async-http-client-project-2.1.0-RC2
async-http-client-project-2.1.0-RC3
async-http-client-project-2.1.0-RC4
async-http-client-project-2.1.0-alpha10
async-http-client-project-2.1.0-alpha11
async-http-client-project-2.1.0-alpha12
async-http-client-project-2.1.0-alpha13
async-http-client-project-2.1.0-alpha14
async-http-client-project-2.1.0-alpha15
async-http-client-project-2.1.0-alpha16
async-http-client-project-2.1.0-alpha17
async-http-client-project-2.1.0-alpha18
async-http-client-project-2.1.0-alpha19
async-http-client-project-2.1.0-alpha2
async-http-client-project-2.1.0-alpha20
async-http-client-project-2.1.0-alpha21
async-http-client-project-2.1.0-alpha22
async-http-client-project-2.1.0-alpha23
async-http-client-project-2.1.0-alpha24
async-http-client-project-2.1.0-alpha25
async-http-client-project-2.1.0-alpha26
async-http-client-project-2.1.0-alpha3
async-http-client-project-2.1.0-alpha4
async-http-client-project-2.1.0-alpha5
async-http-client-project-2.1.0-alpha6
async-http-client-project-2.1.0-alpha7
async-http-client-project-2.1.0-alpha8
async-http-client-project-2.1.0-alpha9
async-http-client-project-2.1.1
async-http-client-project-2.1.2
async-http-client-project-2.10.0
async-http-client-project-2.10.1
async-http-client-project-2.10.2
async-http-client-project-2.10.3
async-http-client-project-2.10.4
async-http-client-project-2.10.5
async-http-client-project-2.11.0
async-http-client-project-2.12.0
async-http-client-project-2.12.1
async-http-client-project-2.12.2
async-http-client-project-2.12.3
async-http-client-project-2.12.4
async-http-client-project-2.14.5
async-http-client-project-2.15.0
async-http-client-project-2.16.0
async-http-client-project-2.2.0
async-http-client-project-2.2.1
async-http-client-project-2.3.0
async-http-client-project-2.4.0
async-http-client-project-2.4.1
async-http-client-project-2.4.2
async-http-client-project-2.4.3
async-http-client-project-2.4.4
async-http-client-project-2.4.5
async-http-client-project-2.4.6
async-http-client-project-2.4.7
async-http-client-project-2.4.8
async-http-client-project-2.4.9
async-http-client-project-2.5.0
async-http-client-project-2.5.1
async-http-client-project-2.5.2
async-http-client-project-2.5.3
async-http-client-project-2.5.4
async-http-client-project-2.6.0
async-http-client-project-2.7.0
async-http-client-project-2.8.0
async-http-client-project-2.8.1
async-http-client-project-2.9.0
async-http-client-project-3.*
async-http-client-project-3.0.0
async-http-client-project-3.0.1
async-http-client-project-3.0.10
async-http-client-project-3.0.11
async-http-client-project-3.0.12
async-http-client-project-3.0.2
async-http-client-project-3.0.3
async-http-client-project-3.0.4
async-http-client-project-3.0.5
async-http-client-project-3.0.6
async-http-client-project-3.0.7
async-http-client-project-3.0.8
async-http-client-project-3.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107281.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "288730145480338461962172404755049731948",
            "length": 327
        },
        "id": "CVE-2026-107281-0589ee7c",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/AsyncHttpClientHandler.java",
            "function": "finishUpdate"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "51616862176537487450775212183040078711",
            "length": 3160
        },
        "id": "CVE-2026-107281-15b37657",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java",
            "function": "exitAfterHandlingRedirect"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "223012992018971433217073035018353617495",
                "260928949143965625216228429390615520694",
                "144933053861689910150682866581558024210",
                "275610558554123132140596225591817034499",
                "126925599087567496020378534943260354412",
                "47050140889884445704261638847428305410",
                "153890858470430959851797015456599118764",
                "323210720716027054157334774983550825676"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107281-1768647b",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "219246596221720898981563676126452787927",
                "112413554918931264338179563940130289539",
                "262908889413526511266896616639455764237"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107281-26220b3f",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "278349082742419654169212630117273520780",
            "length": 3240
        },
        "id": "CVE-2026-107281-2bad9088",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java",
            "function": "exitAfterHandlingRedirect"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "20330549020912931133227266814408619469",
            "length": 482
        },
        "id": "CVE-2026-107281-2c616334",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java",
            "function": "pollPooledChannel"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "223012992018971433217073035018353617495",
                "260928949143965625216228429390615520694",
                "240544823618641810682492508157506598841",
                "7449607784923438107087451227101050276",
                "126925599087567496020378534943260354412",
                "47050140889884445704261638847428305410",
                "153890858470430959851797015456599118764",
                "170534849440382169764625176003874828809"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107281-33808d30",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "331132602917146773837631122170563207103",
            "length": 939
        },
        "id": "CVE-2026-107281-3ed5bd6a",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java",
            "function": "replayRequest"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "89708691802783241181137648851968082998",
            "length": 123
        },
        "id": "CVE-2026-107281-5be06b7d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java",
            "function": "drainChannelAndOffer"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "327841583408810174882727307259366418457",
                "225856860697427524412922987284257857697",
                "51257216243098803863131068348992798560",
                "228989682229619968745464014755724360540",
                "319665170600263907654050432177095818664",
                "113080282653837900945173783955297452512",
                "336058670116607470849419202969332581285",
                "160058220258090674048435543249555965928"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107281-6c8f74b3",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/AsyncHttpClientHandler.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "288730145480338461962172404755049731948",
            "length": 327
        },
        "id": "CVE-2026-107281-76dc2812",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/AsyncHttpClientHandler.java",
            "function": "finishUpdate"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "89708691802783241181137648851968082998",
            "length": 123
        },
        "id": "CVE-2026-107281-880b9f6c",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java",
            "function": "drainChannelAndOffer"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "208038687406667484958729831464410022470",
                "58309572727667912865549178078357225101",
                "275740222303063859441307579401870662191",
                "3706280016868164320978224880517816544",
                "79311042076409514056309114404386819167",
                "99135657026062383629714676693144318205",
                "108722099215827632157783584217716810918",
                "231592124670771851231841792592778580575",
                "240608507889312564265508033419256884139",
                "250803485582796011298073074569254702939",
                "308876809136388913929276664471295871098",
                "149393809071478709505946281990802958605",
                "160645704852117574973522885100840227388",
                "249172951662678749534536580337439913835",
                "244631750887743614148967642982326203865",
                "165215327185258329068577322101145385685",
                "222567340153444217976560473832578952507",
                "7250222536701251939383982077645943108",
                "9068377061838886497670338903994837969"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107281-a30d3273",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "327841583408810174882727307259366418457",
                "225856860697427524412922987284257857697",
                "51257216243098803863131068348992798560",
                "228989682229619968745464014755724360540",
                "319665170600263907654050432177095818664",
                "113080282653837900945173783955297452512",
                "336058670116607470849419202969332581285",
                "160058220258090674048435543249555965928"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107281-b0f0cfc3",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/AsyncHttpClientHandler.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "78898404868275482304696245035362744337",
            "length": 1376
        },
        "id": "CVE-2026-107281-b774c831",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java",
            "function": "pollPooledChannel"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "290083453370474412497177000962957828819",
                "252993441232014134897406815816077590655",
                "278504100699472608190267584753781311223",
                "183637216311738231097493231616565295217",
                "280623017119974790291096562373203240203",
                "315845315827709108031466988960321070936",
                "93187974517077857492175201020565040781",
                "28930214874688961451802198363549372521",
                "165215327185258329068577322101145385685",
                "222567340153444217976560473832578952507",
                "7250222536701251939383982077645943108",
                "9068377061838886497670338903994837969"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107281-c6927e24",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "319981061666573934872902157208912328509",
            "length": 685
        },
        "id": "CVE-2026-107281-c7b286ac",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java",
            "function": "add"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "185973529296049735474105907057052587611",
            "length": 1098
        },
        "id": "CVE-2026-107281-d785d397",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestSender.java",
            "function": "replayRequest"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "227454738693993203136368648783413201493",
                "173821234568441741612041921533159820472",
                "186484411045948665807222152173473212150",
                "224693335022652767092140525341883717127",
                "339658646034294281944169177073152799128",
                "174709020745150500971144237594942952841",
                "117457524716875049023775804107575228539",
                "98093989558677756028346503501459784145"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107281-eaad4c77",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "339658646034294281944169177073152799128",
                "174709020745150500971144237594942952841",
                "117457524716875049023775804107575228539",
                "98093989558677756028346503501459784145"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107281-f9597278",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java"
        }
    }
]
vanir_signatures_modified
"2026-10-09T07:06:52Z"