CVE-2026-107281: AsyncHttpClient: Connection pool key omits the authenticated principal, so an NTLM or Negotiate connection is reused across identities
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key excludes the authenticated principal for connection-oriented NTLM and Negotiate authentication. A pooled socket authenticated for one request can be reused by a request carrying another principal, and the server executes that later request as the first identity. Basic and Digest are not affected because they authenticate each request. This issue is fixed in versions 3.0.13 and 2.16.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AsyncHttpClientto a version that resolves this vulnerability.Fixed in 3.0.13 - Upgrade
Upgrade
AsyncHttpClientto a version that resolves this vulnerability.Fixed in 2.16.1
Event History
Frequently Asked Questions
Which deployments are exposed to cross-identity request execution?
Java applications using AsyncHttpClient with HTTP/1.1 connection pooling and connection-oriented NTLM or Negotiate authentication are exposed. Basic and Digest authentication are not affected because they authenticate every request.
What conditions are needed for exploitation?
A socket already authenticated for one principal must remain in the pool and be reused for a later request carrying a different principal. The server then executes the later request as the identity associated with the existing connection.
What versions contain the fix?
Upgrade to AsyncHttpClient 3.0.13 or 2.16.1. Versions prior to those releases are affected.