{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/async-http-client--3.0.12/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:asynchttpclient:async_http_client:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-107282"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["async-http-client (\u003c= 2.16.0)","async-http-client (\u003c= 3.0.12)","async-http-client (\u003c 3.0.14)","async-http-client (\u003c= 2.16.1)"],"_cs_severities":["critical"],"_cs_tags":["credential-theft","data-leakage","library-vulnerability","authentication-bypass","cve-2026-107230","java"],"_cs_type":"advisory","_cs_vendors":["AsyncHttpClient"],"content_html":"\u003cp\u003eAsyncHttpClient (v2.x \u0026lt;= 2.16.0 and v3.x \u0026lt;= 3.0.12) contains a critical vulnerability, CVE-2026-107282, that leads to the leakage of credentials and sensitive request data. The issue stems from the library's handling of request replays and failover patterns - triggered by \u003ccode\u003eResponseFilter\u003c/code\u003e or automatic \u003ccode\u003eIOException\u003c/code\u003e retries. When a request is replayed to a different host, the internal \u003ccode\u003etargetRequest\u003c/code\u003e pointer is not updated to match the new host, leaving it pointing to the original destination.\u003c/p\u003e\n\u003cp\u003eAs a result, subsequent connection pool operations, tunneling requests, and realm-based authentication processes use stale request data. This leads to the application sending sensitive headers, such as \u003ccode\u003eAuthorization\u003c/code\u003e, to the wrong host. Furthermore, if the protocol upgrades from HTTP to HTTPS during the replay, the client may fail to install an SSL handler, causing the transmission of credentials in cleartext. Defenders should note that this behavior occurs via documented features, making it a design-level defect rather than a recent regression.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn application configured with AsyncHttpClient attempts to perform a failover or retry operation upon encountering an error.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eResponseFilter\u003c/code\u003e or \u003ccode\u003eIOException\u003c/code\u003e retry path triggers a request replay to a new destination host (Host B).\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eNettyRequestSender\u003c/code\u003e component initiates the request but fails to update the target request object, retaining the original destination (Host A) headers and metadata.\u003c/li\u003e\n\u003cli\u003eThe client's connection pool incorrectly keys the connection to Host B under the identity of Host A.\u003c/li\u003e\n\u003cli\u003eSubsequent authentication routines read the stale target request, attaching Host A's \u003ccode\u003eAuthorization\u003c/code\u003e header to the traffic destined for Host B.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eNettyConnectListener\u003c/code\u003e logic fails to install an SSL handler if the original request was HTTP and the replay is HTTPS, bypassing intended security controls.\u003c/li\u003e\n\u003cli\u003eThe replayed request - containing sensitive data - is transmitted to Host B, resulting in unauthorized credential exposure.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in the unauthorized exposure of authentication credentials and potentially sensitive request content to third-party or unauthorized hosts. This impact is significant for applications that utilize connection pooling, automated failover, or retry mechanisms in environments requiring strict confidentiality. Any service integrated with this library in these versions is susceptible to credential harvesting if an adversary controls or can intercept the replayed destination.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to version 3.0.13 or 2.16.1 of \u003ccode\u003easync-http-client\u003c/code\u003e immediately to patch the target request management logic.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, disable \u003ccode\u003eResponseFilter\u003c/code\u003e logic that redirects requests to different hosts.\u003c/li\u003e\n\u003cli\u003eDisable automatic request retries for applications configured with credentials or that operate via proxies to mitigate the risk of accidental credential leakage during failover scenarios.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T19:27:09Z","date_published":"2026-10-08T19:25:36Z","id":"https://feed.craftedsignal.io/briefs/2026-10-asynchttpclient-replay-leak/","summary":"A vulnerability in AsyncHttpClient causes sensitive credentials and request details to be leaked to unintended hosts when a request replay or failover is triggered.","title":"AsyncHttpClient Credential and Request Leakage via Host Replay","url":"https://feed.craftedsignal.io/briefs/2026-10-asynchttpclient-replay-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - Async-Http-Client (\u003c= 3.0.12)","version":"https://jsonfeed.org/version/1.1"}