CVE-2026-107282 | AsyncHttpClient up to 2.16.0/3.0.12 Connection Pool Selection authentication replay

SecurityVulns

A vulnerability, which was classified as critical, has been found in AsyncHttpClient up to 2.16.0/3.0.12. Affected by this issue is some unknown functionality of the component Connection Pool Selection. Performing a manipulation results in authentication bypass by capture-replay.

This vulnerability is known as CVE-2026-107282. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More