AsyncHttpClient Credential and Request Leakage via Host Replay
A vulnerability in AsyncHttpClient causes sensitive credentials and request details to be leaked to unintended hosts when a request replay or failover is triggered.
CVE search metadata
CVE search record: CVE-2026-107282. KEV: no. Product: async-http-client (<= 2.16.0), async-http-client (<= 3.0.12), async-http-client (< 3.0.14), async-http-client (<= 2.16.1). Brief: AsyncHttpClient Credential and Request Leakage via Host Replay. Brief link: https://feed.craftedsignal.io/briefs/2026-10-asynchttpclient-replay-leak/
What's new
- 1. added coverage for async-http-client (< 3.0.14) +1 products Oct 8, 19:27 via ghsa
AsyncHttpClient (v2.x <= 2.16.0 and v3.x <= 3.0.12) contains a critical vulnerability, CVE-2026-107282, that leads to the leakage of credentials and sensitive request data. The issue stems from the library's handling of request replays and failover patterns - triggered by ResponseFilter or automatic IOException retries. When a request is replayed to a different host, the internal targetRequest pointer is not updated to match the new host, leaving it pointing to the original destination.
As a result, subsequent connection pool operations, tunneling requests, and realm-based authentication processes use stale request data. This leads to the application sending sensitive headers, such as Authorization, to the wrong host. Furthermore, if the protocol upgrades from HTTP to HTTPS during the replay, the client may fail to install an SSL handler, causing the transmission of credentials in cleartext. Defenders should note that this behavior occurs via documented features, making it a design-level defect rather than a recent regression.
Attack Chain
- An application configured with AsyncHttpClient attempts to perform a failover or retry operation upon encountering an error.
- The
ResponseFilterorIOExceptionretry path triggers a request replay to a new destination host (Host B). - The
NettyRequestSendercomponent initiates the request but fails to update the target request object, retaining the original destination (Host A) headers and metadata. - The client's connection pool incorrectly keys the connection to Host B under the identity of Host A.
- Subsequent authentication routines read the stale target request, attaching Host A's
Authorizationheader to the traffic destined for Host B. - The
NettyConnectListenerlogic fails to install an SSL handler if the original request was HTTP and the replay is HTTPS, bypassing intended security controls. - The replayed request - containing sensitive data - is transmitted to Host B, resulting in unauthorized credential exposure.
Impact
The vulnerability results in the unauthorized exposure of authentication credentials and potentially sensitive request content to third-party or unauthorized hosts. This impact is significant for applications that utilize connection pooling, automated failover, or retry mechanisms in environments requiring strict confidentiality. Any service integrated with this library in these versions is susceptible to credential harvesting if an adversary controls or can intercept the replayed destination.
Recommendation
- Upgrade to version 3.0.13 or 2.16.1 of
async-http-clientimmediately to patch the target request management logic. - If upgrading is not immediately possible, disable
ResponseFilterlogic that redirects requests to different hosts. - Disable automatic request retries for applications configured with credentials or that operate via proxies to mitigate the risk of accidental credential leakage during failover scenarios.
Immediate actions
Upgrade all instances of async-http-client to version 3.0.13 or 2.16.1.
Mitigations
Disable ResponseFilter failover to different hosts and disable automatic request retries.
CVE-2026-107282