Incorrect authorization in Async-http-client - #VU152423
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to access services as a different authenticated identity.
The vulnerability exists due to incorrect authorization in HTTP connection pool key generation when reusing authenticated origin or proxy connections for requests under different identities. A remote attacker can send a request that reuses a pooled connection authenticated as another identity to access services as a different authenticated identity.
The issue applies to NTLM, Kerberos, and SPNEGO authentication to origins or proxies, as well as SOCKS or CONNECT proxy logins.