CVE-2026-107281
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key excludes the authenticated principal for connection-oriented NTLM and Negotiate authentication. A pooled socket authenticated for one request can be reused by a request carrying another principal, and the server executes that later request as the first identity. Basic and Digest are not affected because they authenticate each request. This issue is fixed in versions 3.0.13 and 2.16.1.
CVSS
- Version: 4.0
- Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Base score: 7.6
Exploitation probability (EPSS)
FIRST hasn't scored this CVE yet (usual for very recent or rejected CVEs).
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1210Exploitation of Remote Serviceslateral movement75 % - Primary impact
T1078Valid Accountsstealth · persistence · privilege escalation · initial access85 % - Secondary impact
T1548Abuse Elevation Control Mechanismprivilege escalation70 %
Vulnerabilidad en pool de conexiones HTTP que reutiliza sockets NTLM/Negotiate autenticados para otra identidad; requiere PR:L. Impacto: suplantación de cuenta (T1078) y elevación de privilegios (T1548) al ejecutar solicitudes con identidad ajena.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-346, CWE-863
References
- https://github.com/AsyncHttpClient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d
- https://github.com/AsyncHttpClient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e
- https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
- https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-vvp4-63h8-v5pm
Raw JSON (NVD)
Show
{
"id": "CVE-2026-107281",
"cveTags": [],
"metrics": {
"cvssMetricV40": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 7.6,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"privilegesRequired": "LOW",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "AsyncHttpClient",
"product": "async-http-client",
"versions": [
{
"status": "affected",
"version": ">= 3.0.0, < 3.0.13"
},
{
"status": "affected",
"version": ">= 2.0.0, < 2.16.1"
}
]
}
]
}
],
"published": "2026-10-07T22:17:03.980",
"references": [
{
"url": "https://github.com/AsyncHttpClient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/AsyncHttpClient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-vvp4-63h8-v5pm",
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Received",
"weaknesses": [
{
"type": "Primary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-346"
},
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key excludes the authenticated principal for connection-oriented NTLM and Negotiate authentication. A pooled socket authenticated for one request can be reused by a request carrying another principal, and the server executes that later request as the first identity. Basic and Digest are not affected because they authenticate each request. This issue is fixed in versions 3.0.13 and 2.16.1."
}
],
"lastModified": "2026-10-07T22:17:03.980",
"sourceIdentifier": "security-advisories@github.com"
}