External risk intelligence

AsyncHttpClient Cross-Host Request Replay Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-107282

This vulnerability exists within the AsyncHttpClient library, a dependency used by Java applications to perform outgoing HTTP requests. While the library handles network traffic, it is a developer-focused toolkit rather than a standalone network service or edge-facing appliance. Public exposure is uncommon as the risk depends on how individual applications implement the library for specific outgoing request logic.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a security flaw in the AsyncHttpClient library used by Java applications. The issue could lead to sensitive information, such as authentication credentials, being unintentionally exposed to unintended destinations when certain request replay scenarios occur. The main concern is to confirm if our environment utilizes this specific library and, if so, to understand the potential exposure.

  • Sensitive data exposure risk.
  • Affects Java applications using a common library.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could potentially exploit this vulnerability by crafting specific HTTP requests that are replayed by an affected library. This replay mechanism, triggered under certain documented retry or failover conditions, can cause the library to inadvertently send sensitive information, such as credentials or the original request's path, to an unintended destination. The risk is that this could expose original request details to a different host than intended.

  • Requires a specific request replay scenario.
  • Triggered by documented failover or retry paths.
  • Risk of exposing original request details.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, sensitive information such as Host headers and Authorization credentials could be replayed to unintended destinations. This may occur when failover or retry paths are triggered within the AsyncHttpClient library, causing subsequent requests to inadvertently use aspects of the original request's context.

  • Host header, authorization data at risk.
  • Cross-host request replay may expose data.
  • Sensitive information sent to wrong host.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Java applications utilizing the AsyncHttpClient library for outgoing HTTP requests. Ownership likely falls to application development teams or platform teams responsible for managing third-party libraries. The immediate first step is to identify all applications using this library, determine their business criticality and exposure, and then coordinate with application owners to plan for updates during the next maintenance window or to implement temporary compensating controls if feasible.

  • Application development teams own the remediation.
  • Verify application use and business criticality.
  • Plan updates or implement temporary controls.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is AsyncHttpClient and what does it do?

AsyncHttpClient is a library for Java applications that manages asynchronous HTTP requests and responses. Developers use this toolkit to handle network communication, such as making API calls or interacting with web services, without blocking the main application execution flow.

What is the vulnerability in CVE-2026-107282?

This is a cross-host request replay issue, categorized as CWE-319, CWE-441, and CWE-522. Essentially, when the library retries a failed request, it may mistakenly reuse the original request's connection settings or security context, sending sensitive data—like authorization tokens or Host headers—to the wrong destination instead of the intended one.

How is this bug triggered during an HTTP request?

The flaw is triggered specifically when the library initiates a failover or retry path following a documented ResponseFilter event. It does not occur during standard, successful requests. If the library logic does not trigger these specific recovery mechanisms, the improper replay behavior is not invoked.

Is my application at risk according to Halo Surface Signal?

Halo Surface Signal indicates that risk is unlikely because AsyncHttpClient is a library embedded within applications, not an edge-facing appliance. Exposure depends entirely on whether your specific application logic uses the library to handle outgoing requests in a way that encounters these failover scenarios.

Do I need to update my software to fix this?

Yes. If your applications rely on AsyncHttpClient, you should coordinate with your development teams to update to version 3.0.13 or 2.16.1. These versions contain the necessary logic changes to correctly reset request context and proxy configurations during retries, preventing the accidental leakage of credentials.

References