CVE-2026-107281 | Async-Http-Client up to 2.16.0/3.0.12 HTTP/1.1 Connection-Pool access control

SecurityVulns

A vulnerability classified as critical has been found in Async-Http-Client up to 2.16.0/3.0.12. Affected is an unknown function of the component HTTP1.1 Connection-Pool. This manipulation causes improper access controls.

This vulnerability appears as CVE-2026-107281. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More