CVE-2026-107284

low

Description

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, WebSocketHandler.upgrade aborts a handshake whose Sec-WebSocket-Accept value is missing or invalid but continues into pipeline installation and onOpen delivery. Frames coalesced with the invalid 101 response can be decoded and delivered from a peer that did not prove the handshake, although the request future fails and the channel closes. This issue is fixed in versions 3.0.12 and 2.16.1.

References

https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rwhr-j9rv-85f8

https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12

https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1

https://github.com/AsyncHttpClient/async-http-client/commit/ccdcaa627db6d96dcc42105212cb3ba5048bd7f9

https://github.com/AsyncHttpClient/async-http-client/commit/75a278550aa9a980009d022fb4e635f9c8738c03

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-94644

Details

Source: Mitre, NVD

Published: 2026-10-07

Updated: 2026-10-08

Risk Information

CVSS v2

Base Score: 2.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 3.7

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Severity: Low

EPSS

EPSS: 0.00138