Listen to this Post
The AsyncHttpClient (AHC) library contains a security vulnerability where request replaying mechanisms through ResponseFilters or IOException retries improperly handle target destination state. When a request is replayed onto a different host, the client updates only the current request while leaving the target request pointer pointing at the original host. Consequently, core components such as the connection pool key derivation, connect interceptors, realm selectors, and SSL handlers read stale values. This behavior causes sensitive data including request content, credentials, or authorization headers to be unintentionally leaked to secondary or cross-origin hosts, potentially over plaintext connections if the scheme downgrades.
DailyCVE Form:
Platform: AsyncHttpClient
Version: 3.0.12
Vulnerability : Request Replay
Severity: Critical
date: 2026-10-08
Prediction: 2026-03-15
What Undercode Say
Commands and Codes
AsyncHttpClient client = asyncHttpClient();
// ResponseFilter triggers request replay to a different target host
ResponseFilter filter = response -> {
// Replays request to an unintended secondary host without updating target pointer
return new FilterContext.Builder(response).replayRequest(true).build();
};
Exploit: (Educational Purposes!)
An attacker leverages applications utilizing built-in failover patterns or custom ResponseFilters that replay requests. When the client invokes a failover path, the target request pointer fails to update alongside the current request. Because connection pool keys and authentication realms rely on stale pointers, subsequent requests containing sensitive session cookies or Authorization headers are routed to alternative hosts, disclosing credentials across trust boundaries.
Protection: from this CVE
Upgrade AsyncHttpClient to version 3.0.13 on the 3.x branch or version 2.16.1 on the 2.x branch. Avoid using custom ResponseFilters that replay requests to different hosts, and disable automatic request retries when handling sensitive credentials or working through proxies.
Impact
Exposure of sensitive authentication headers, credentials, and plaintext traffic to arbitrary secondary hosts, leading to cross-origin data leakage and unauthorized data access across distributed backend services.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

