SB20260928258 - Multiple vulnerabilities in Async-http-client
Published: September 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 vulnerabilities.
1) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access services as a different authenticated identity.
The vulnerability exists due to incorrect authorization in HTTP connection pool key generation when reusing authenticated origin or proxy connections for requests under different identities. A remote attacker can send a request that reuses a pooled connection authenticated as another identity to access services as a different authenticated identity.
The issue applies to NTLM, Kerberos, and SPNEGO authentication to origins or proxies, as well as SOCKS or CONNECT proxy logins.
2) Session Fixation (CVE-ID: N/A)
CWE-ID: CWE-384 - Session Fixation
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject cookies into requests to other hosts.
The vulnerability exists due to incomplete origin checks in the default ThreadSafeCookieStore when processing Set-Cookie headers with Domain attributes from attacker-influenced origins. A remote attacker can cause a cookie to be stored under a key matched by a later request to a different host to inject cookies into requests to other hosts.
Exploitation requires a single AsyncHttpClient instance with its default cookie store enabled to access multiple origins, including an attacker-influenced origin.
3) Improper handling of highly compressed data (CVE-ID: N/A)
CWE-ID: CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in the WebSocket permessage-deflate decompression handler when processing compressed WebSocket messages. A remote attacker can send a specially crafted compressed WebSocket message to cause a denial of service.
Only applications that enable WebSocket compression are affected.
4) Protection mechanism failure (CVE-ID: N/A)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to plant, overwrite, or delete secure cookies.
The vulnerability exists due to improper enforcement of secure cookie protections in ThreadSafeCookieStore when handling Set-Cookie headers received over plaintext HTTP. A remote attacker can respond to a plaintext request with a crafted Set-Cookie header to plant, overwrite, or delete secure cookies.
5) Improper Authentication (CVE-ID: N/A)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to access and act under another user's session.
The vulnerability exists due to improper authentication in CookieStore handling of Cookie headers when an application shares a client and its cookie store among users while setting session cookies with setHeader or addHeader. A remote user can cause a request to be sent with a cookie from another user's session to access or act under another user's session.
The cookie store is enabled by default.
Remediation
Install update from vendor's website.
References
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v2j5-22fr-j62r
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-qjr7-w8pj-pmv9
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-x8v2-478q-2hvg
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-p2jm-6hj6-9rjg
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-2jwh-9rmr-j4xf