CVE-2026-107230 | AsyncHttpClient async-http-client up to 2.16.1/3.0.13 SpnegoEngine/NTLM/Kerberos/SPNEGO/SOCKS/CONNECT access control

SecurityVulns

A vulnerability categorized as critical has been discovered in AsyncHttpClient async-http-client up to 2.16.1/3.0.13. Impacted is an unknown function of the component SpnegoEngine/NTLM/Kerberos/SPNEGO/SOCKS/CONNECT. Such manipulation leads to improper access controls.

This vulnerability is listed as CVE-2026-107230. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More