Skip to content

Menu
  • Home
Menu

CVE-2026-107282 – AsyncHttpClient: Replay to a different host sends the original host request and credentials to the new host

Posted on October 8, 2026
CVE ID :CVE-2026-107282

Published : Oct. 7, 2026, 10:17 p.m. | 1 hour, 12 minutes ago

Description :The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, cross-host request replay updates the current request but leaves the target request and related proxy context pointing at the original origin. Connection-pool selection, CONNECT handling, realm selection, and TLS setup can consequently send the original host’s path, Host header, Authorization credentials, or plaintext request to the replay destination. Documented ResponseFilter failover and retry paths can trigger the replay. This issue is fixed in versions 3.0.13 and 2.16.1.

Severity: 9.4 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

🤖 AI-Generated Patch Solution

Google Gemini (gemini-2.5-flash) • CVE: CVE-2026-107282

Unknown
N/A
⚠️ Vulnerability Description:

1. IMMEDIATE ACTIONS

Immediately disconnect or isolate any systems running the vulnerable component from external networks and, if possible, from non-essential internal networks to prevent further compromise, lateral movement, or data exfiltration.
Implement temporary firewall rules or Access Control List (ACL) entries to block all non-essential inbound and outbound network traffic to the affected service port(s) and IP addresses. This should include blocking access from the internet and any non-trusted internal segments.
Scrutinize all available application, web server, and system logs (e.g., access logs, error logs, security event logs, process logs, authentication logs) on affected systems for any indicators of compromise (IOCs). Look for unusual process spawns (e.g., unexpected shell processes), unexpected outbound network connections from the application's user or process, unauthorized file modifications, suspicious user account creation, or abnormal resource utilization. Extend the log review period to several weeks or months if possible, as exploitation might have occurred prior to disclosure.
Engage your organization's incident response team or procedures immediately to assess the scope of potential compromise, contain the threat, eradicate any malicious artifacts, and recover affected systems.

2. PATCH AND UPDATE INFORMATION

Actively monitor the official vendor security advisories, mailing lists, and support portals for the specific software component, framework, or product identified as vulnerable to CVE-2026-1

💡 AI-generated — review with a security professional before acting.View on NVD →
Post Views: 2

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme