Hi,
The following vulnerabilities were published for async-http-client.
CVE-2026-107285[0]:
| The AsyncHttpClient (AHC) library allows Java applications to easily
| execute HTTP requests and asynchronously process HTTP responses.
| Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through
| CONNECT, but NettyRequestFactory.newNettyRequest and requestUri
| decide whether to attach proxy authentication and an absolute-form
| target only from whether the URI is secure. Because ws is not marked
| secure, the tunneled WebSocket upgrade sent to the origin includes
| the proxy's Proxy-Authorization value. Basic credentials are
| directly recoverable and Digest responses can be replayed or cracked
| offline. This issue is fixed in versions 3.0.12 and 2.16.1.
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-3wp9-xfwm-rjjf
https://github.com/AsyncHttpClient/async-http-client/commit/c4feab0f7f86d61505a48e40d383c8a375a22e18 (async-http-client-project-2.16.1)
CVE-2026-107284[1]:
| The AsyncHttpClient (AHC) library allows Java applications to easily
| execute HTTP requests and asynchronously process HTTP responses.
| Prior to 3.0.12 and 2.16.1, WebSocketHandler.upgrade aborts a
| handshake whose Sec-WebSocket-Accept value is missing or invalid but
| continues into pipeline installation and onOpen delivery. Frames
| coalesced with the invalid 101 response can be decoded and delivered
| from a peer that did not prove the handshake, although the request
| future fails and the channel closes. This issue is fixed in versions
| 3.0.12 and 2.16.1.
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rwhr-j9rv-85f8
https://github.com/AsyncHttpClient/async-http-client/commit/75a278550aa9a980009d022fb4e635f9c8738c03 (async-http-client-project-2.16.1)
CVE-2026-107283[2]:
| The AsyncHttpClient (AHC) library allows Java applications to easily
| execute HTTP requests and asynchronously process HTTP responses.
| Prior to 3.0.12 and 2.16.1, Realm.Builder generates the HTTP Digest
| client nonce with ThreadLocalRandom rather than a cryptographically
| secure random source. Digest relies on an unpredictable cnonce to
| resist chosen-plaintext and credential precomputation attacks, so an
| observer able to infer generator state can reduce the protection of
| the authentication exchange. This issue is fixed in versions 3.0.12
| and 2.16.1.
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-mfj3-87qq-382v
https://github.com/AsyncHttpClient/async-http-client/commit/e1f5fc88fe211d3f64032c33b91093ba3d5e793d (async-http-client-project-2.16.1)
CVE-2026-107282[3]:
| The AsyncHttpClient (AHC) library allows Java applications to easily
| execute HTTP requests and asynchronously process HTTP responses.
| Prior to 3.0.13 and 2.16.1, cross-host request replay updates the
| current request but leaves the target request and related proxy
| context pointing at the original origin. Connection-pool selection,
| CONNECT handling, realm selection, and TLS setup can consequently
| send the original host's path, Host header, Authorization
| credentials, or plaintext request to the replay destination.
| Documented ResponseFilter failover and retry paths can trigger the
| replay. This issue is fixed in versions 3.0.13 and 2.16.1.
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-jmqq-x5g9-9p2w
https://github.com/AsyncHttpClient/async-http-client/commit/bbc31aed3b044f9f7a126cf689a8c8d7ad2ae1cb (async-http-client-project-2.16.1)
CVE-2026-107281[4]:
| The AsyncHttpClient (AHC) library allows Java applications to easily
| execute HTTP requests and asynchronously process HTTP responses.
| Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key
| excludes the authenticated principal for connection-oriented NTLM
| and Negotiate authentication. A pooled socket authenticated for one
| request can be reused by a request carrying another principal, and
| the server executes that later request as the first identity. Basic
| and Digest are not affected because they authenticate each request.
| This issue is fixed in versions 3.0.13 and 2.16.1.
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-vvp4-63h8-v5pm
https://github.com/AsyncHttpClient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d (async-http-client-project-2.16.1)
CVE-2026-107280[5]:
| The AsyncHttpClient (AHC) library allows Java applications to easily
| execute HTTP requests and asynchronously process HTTP responses.
| Prior to 3.0.13 and 2.16.1, ThreadSafeCookieStore validates Domain
| attributes with domain matching but does not reject public suffixes.
| A host beneath a suffix such as co.uk can set a cookie for that
| suffix, after which the shared cookie store sends it to unrelated
| hosts under the suffix. This can inject or overwrite session-
| relevant cookie values across origins. This issue is fixed in
| versions 3.0.13 and 2.16.1.
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-jmqq-x5g9-9p2w
https://github.com/AsyncHttpClient/async-http-client/commit/bbc31aed3b044f9f7a126cf689a8c8d7ad2ae1cb (async-http-client-project-2.16.1)
CVE-2026-107232[6]:
| The AsyncHttpClient (AHC) library allows Java applications to easily
| execute HTTP requests and asynchronously process HTTP responses.
| Prior to 3.0.12 on 3.x and 2.16.1 on 2.x, the client infers that an
| HTTP proxy tunnel exists from the last request method rather than
| the CONNECT result. After a proxy rejects CONNECT, redirect or
| authentication handlers can write an origin request and its
| Authorization credentials onto the still-plaintext proxy connection.
| Basic credentials can be recovered directly, while NTLM responses
| may be cracked or relayed. This issue is fixed in versions 3.0.12
| and 2.16.1.
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v9f2-7rw2-gr2x
https://github.com/AsyncHttpClient/async-http-client/commit/3a625cb892233c0a6653ac68823a25ffbc80f393 (async-http-client-project-2.16.1)
CVE-2026-107231[7]:
| The AsyncHttpClient (AHC) library allows Java applications to easily
| execute HTTP requests and asynchronously process HTTP responses.
| Prior to 3.0.13 and 2.16.1, Realm.Builder treats a Digest challenge
| that yields no usable nonce as a Basic challenge. A malicious origin
| or proxy can label a challenge Digest while omitting or emptying the
| nonce, causing the client to resend the username and password using
| reversible Basic authentication. Both origin and proxy challenge
| parsers are affected. This issue is fixed in versions 3.0.13 and
| 2.16.1.
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rqf5-2wxv-rjf4
https://github.com/AsyncHttpClient/async-http-client/commit/c8d639bf6ac341d377d610a93570bcd15565f1a6 (async-http-client-project-2.16.1)
CVE-2026-107230[8]:
| The AsyncHttpClient (AHC) library allows Java applications to easily
| execute HTTP requests and asynchronously process HTTP responses.
| From 2.0.0 until 3.0.14, connection-pool partitioning still omits
| identity-defining fields for Kerberos, SPNEGO, NTLM, and
| authenticated proxy connections. Logins without a configured
| principal, proxy realms, identities sharing a user name, and SOCKS
| or CONNECT proxy logins can reuse a socket authenticated as a
| different identity. A later request is then executed under the first
| identity and can expose that identity's data or authority to another
| caller. In the affected execution path, SpnegoEngine, NTLM,
| Kerberos, SPNEGO, SOCKS, and CONNECT control or expose the
| vulnerable behavior. This issue is fixed in version 3.0.14.
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v2j5-22fr-j62r
https://github.com/AsyncHttpClient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054 (async-http-client-project-3.0.14)
CVE-2026-107229[9]:
| The AsyncHttpClient (AHC) library allows Java applications to easily
| execute HTTP requests and asynchronously process HTTP responses.
| From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely
| validates cookie Domain attributes. Missing private-section and
| default public-suffix rules, absent A-label normalization, locale-
| sensitive lowercasing, public-suffix host-only handling, and numeric
| or IP host checks allow one origin to store a cookie later sent to
| another origin. Applications sharing one client across trust domains
| can therefore receive attacker-injected cookies and may be exposed
| to session fixation. This issue is fixed in version 3.0.14.
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-qjr7-w8pj-pmv9
https://github.com/AsyncHttpClient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9 (async-http-client-project-3.0.14)
CVE-2026-107228[10]:
| The AsyncHttpClient (AHC) library allows Java applications to easily
| execute HTTP requests and asynchronously process HTTP responses.
| From 2.1.0 until 3.0.14, the enabled-by-default cookie store
| replaces a Cookie header explicitly supplied through setHeader or
| addHeader whenever the store contributes any cookie for the origin.
| In a shared client, stored cookies originating from one user can
| replace a different user's request cookie, causing the request to
| execute under the wrong session. This bypasses the earlier
| CVE-2024-53990 remediation, which covered cookies supplied through
| addCookie but not a directly supplied header. This issue is fixed in
| version 3.0.14.
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-2jwh-9rmr-j4xf
https://github.com/AsyncHttpClient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f (async-http-client-project-3.0.14)
CVE-2026-107227[11]:
| The AsyncHttpClient (AHC) library allows Java applications to easily
| execute HTTP requests and asynchronously process HTTP responses.
| From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression
| is unbounded when compression is enabled. The inbound pipeline
| aggregates compressed frames before
| WebSocketClientCompressionHandler inflates them, so
| webSocketMaxFrameSize and webSocketMaxBufferSize do not bound
| decompressed output. A malicious WebSocket peer can send a small
| compressed message that expands to a very large Netty buffer and
| exhausts JVM heap. This issue is fixed in version 3.0.14.
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-x8v2-478q-2hvg
https://github.com/AsyncHttpClient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30 (async-http-client-project-3.0.14)
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-107285
https://www.cve.org/CVERecord?id=CVE-2026-107285
[1] https://security-tracker.debian.org/tracker/CVE-2026-107284
https://www.cve.org/CVERecord?id=CVE-2026-107284
[2] https://security-tracker.debian.org/tracker/CVE-2026-107283
https://www.cve.org/CVERecord?id=CVE-2026-107283
[3] https://security-tracker.debian.org/tracker/CVE-2026-107282
https://www.cve.org/CVERecord?id=CVE-2026-107282
[4] https://security-tracker.debian.org/tracker/CVE-2026-107281
https://www.cve.org/CVERecord?id=CVE-2026-107281
[5] https://security-tracker.debian.org/tracker/CVE-2026-107280
https://www.cve.org/CVERecord?id=CVE-2026-107280
[6] https://security-tracker.debian.org/tracker/CVE-2026-107232
https://www.cve.org/CVERecord?id=CVE-2026-107232
[7] https://security-tracker.debian.org/tracker/CVE-2026-107231
https://www.cve.org/CVERecord?id=CVE-2026-107231
[8] https://security-tracker.debian.org/tracker/CVE-2026-107230
https://www.cve.org/CVERecord?id=CVE-2026-107230
[9] https://security-tracker.debian.org/tracker/CVE-2026-107229
https://www.cve.org/CVERecord?id=CVE-2026-107229
[10] https://security-tracker.debian.org/tracker/CVE-2026-107228
https://www.cve.org/CVERecord?id=CVE-2026-107228
[11] https://security-tracker.debian.org/tracker/CVE-2026-107227
https://www.cve.org/CVERecord?id=CVE-2026-107227
Please adjust the affected versions in the BTS as needed.