CVE-2026-45300
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin, the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip the `Cookie` header, causing session cookies and other sensitive cookie values to be sent to attacker-controlled servers. Versions 2.15.0 and 3.0.10 patch the issue.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
- Puntuación base: 7.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.46%
- Percentil entre todas las CVEs puntuadas: 38
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution75 % - Impacto principal
T1005Data from Local Systemcollection85 %
Requiere interacción del usuario (UI:R) para seguir un redirect malicioso; filtra cookies sensibles (CWE-200) a servidores controlados por atacante.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-200
Referencias
- https://github.com/AsyncHttpClient/async-http-client/commit/3b0e3e9e
- https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.10
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-fmxf-pm6p-7xgm
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-fmxf-pm6p-7xgm
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-45300",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-45300",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-08T14:33:01.603361Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.4,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "AsyncHttpClient",
"product": "async-http-client",
"versions": [
{
"status": "affected",
"version": ">= 3.0.0.Beta1, < 3.0.10"
},
{
"status": "affected",
"version": ">= 2.0.0, < 2.15.0"
}
]
}
]
}
],
"published": "2026-06-05T20:17:31.893",
"references": [
{
"url": "https://github.com/AsyncHttpClient/async-http-client/commit/3b0e3e9e",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.10",
"tags": [
"Product",
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-fmxf-pm6p-7xgm",
"tags": [
"Exploit",
"Mitigation",
"Patch",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-fmxf-pm6p-7xgm",
"tags": [
"Exploit",
"Mitigation",
"Patch",
"Vendor Advisory"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin, the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip the `Cookie` header, causing session cookies and other sensitive cookie values to be sent to attacker-controlled servers. Versions 2.15.0 and 3.0.10 patch the issue."
},
{
"lang": "es",
"value": "La biblioteca AsyncHttpClient (AHC) permite a las aplicaciones Java ejecutar fácilmente solicitudes HTTP y procesar asincrónicamente respuestas HTTP. Las versiones de la rama 2.x anteriores a la 2.15.0 y de la rama 3.x anteriores a la 3.0.10 filtran encabezados 'Cookie' a destinos de redirección de origen cruzado. Al seguir una redirección a un origen diferente, el método 'propagatedHeaders()' en 'Redirect30xInterceptor.java' elimina los encabezados 'Authorization' y 'Proxy-Authorization' pero no elimina el encabezado 'Cookie', lo que provoca que las cookies de sesión y otros valores de cookie sensibles se envíen a servidores controlados por el atacante. Las versiones 2.15.0 y 3.0.10 corrigen el problema."
}
],
"lastModified": "2026-07-23T07:10:00.113",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:asynchttpclient_project:async-http-client:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF0C317B-18A8-406E-BFF2-0EE6DA050379",
"versionEndExcluding": "2.15.0",
"versionStartIncluding": "2.0.0"
},
{
"criteria": "cpe:2.3:a:asynchttpclient_project:async-http-client:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BD280C21-CB2D-4169-ABD1-CBF918370B32",
"versionEndExcluding": "3.0.10",
"versionStartIncluding": "3.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}