CVE-2026-107284 | async-http-client up to 2.16.0/3.0.11 Handshake WebSocketHandler.upgrade Sec-WebSocket-Accept input validation

SecurityVulns

A vulnerability, which was classified as problematic, was found in async-http-client up to 2.16.0/3.0.11. This affects the function WebSocketHandler.upgrade of the component Handshake. Executing a manipulation of the argument Sec-WebSocket-Accept can lead to improper input validation.

This vulnerability is handled as CVE-2026-107284. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More