<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Async-Http-Client (&lt; 3.0.14) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/async-http-client--3.0.14/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 19:25:36 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/async-http-client--3.0.14/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>AsyncHttpClient Credential and Request Leakage via Host Replay</title><link>https://feed.craftedsignal.io/briefs/2026-10-asynchttpclient-replay-leak/</link><pubDate>Thu, 08 Oct 2026 19:25:36 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-asynchttpclient-replay-leak/</guid><description>A vulnerability in AsyncHttpClient causes sensitive credentials and request details to be leaked to unintended hosts when a request replay or failover is triggered.</description><content:encoded><![CDATA[<p>AsyncHttpClient (v2.x &lt;= 2.16.0 and v3.x &lt;= 3.0.12) contains a critical vulnerability, CVE-2026-107282, that leads to the leakage of credentials and sensitive request data. The issue stems from the library's handling of request replays and failover patterns - triggered by <code>ResponseFilter</code> or automatic <code>IOException</code> retries. When a request is replayed to a different host, the internal <code>targetRequest</code> pointer is not updated to match the new host, leaving it pointing to the original destination.</p>
<p>As a result, subsequent connection pool operations, tunneling requests, and realm-based authentication processes use stale request data. This leads to the application sending sensitive headers, such as <code>Authorization</code>, to the wrong host. Furthermore, if the protocol upgrades from HTTP to HTTPS during the replay, the client may fail to install an SSL handler, causing the transmission of credentials in cleartext. Defenders should note that this behavior occurs via documented features, making it a design-level defect rather than a recent regression.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An application configured with AsyncHttpClient attempts to perform a failover or retry operation upon encountering an error.</li>
<li>The <code>ResponseFilter</code> or <code>IOException</code> retry path triggers a request replay to a new destination host (Host B).</li>
<li>The <code>NettyRequestSender</code> component initiates the request but fails to update the target request object, retaining the original destination (Host A) headers and metadata.</li>
<li>The client's connection pool incorrectly keys the connection to Host B under the identity of Host A.</li>
<li>Subsequent authentication routines read the stale target request, attaching Host A's <code>Authorization</code> header to the traffic destined for Host B.</li>
<li>The <code>NettyConnectListener</code> logic fails to install an SSL handler if the original request was HTTP and the replay is HTTPS, bypassing intended security controls.</li>
<li>The replayed request - containing sensitive data - is transmitted to Host B, resulting in unauthorized credential exposure.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The vulnerability results in the unauthorized exposure of authentication credentials and potentially sensitive request content to third-party or unauthorized hosts. This impact is significant for applications that utilize connection pooling, automated failover, or retry mechanisms in environments requiring strict confidentiality. Any service integrated with this library in these versions is susceptible to credential harvesting if an adversary controls or can intercept the replayed destination.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade to version 3.0.13 or 2.16.1 of <code>async-http-client</code> immediately to patch the target request management logic.</li>
<li>If upgrading is not immediately possible, disable <code>ResponseFilter</code> logic that redirects requests to different hosts.</li>
<li>Disable automatic request retries for applications configured with credentials or that operate via proxies to mitigate the risk of accidental credential leakage during failover scenarios.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>credential-theft</category><category>data-leakage</category><category>library-vulnerability</category><category>authentication-bypass</category><category>cve-2026-107230</category><category>java</category></item></channel></rss>