AsyncHttpClient, Request Replay, CVE-2026-107232 (Critical) -DC-Oct2026-2922

Listen to this Post

The AsyncHttpClient (AHC) library contains a security vulnerability where request replaying mechanisms through ResponseFilters or IOException retries improperly handle target destination state. When a request is replayed onto a different host, the client updates only the current request while leaving the target request pointer pointing at the original host. Consequently, core components such as the connection pool key derivation, connect interceptors, realm selectors, and SSL handlers read stale values. This behavior causes sensitive data including request content, credentials, or authorization headers to be unintentionally leaked to secondary or cross-origin hosts, potentially over plaintext connections if the scheme downgrades.

DailyCVE Form:

Platform: AsyncHttpClient
Version: 3.0.12
Vulnerability : Request Replay
Severity: Critical
date: 2026-10-08

Prediction: 2026-03-15

What Undercode Say

Commands and Codes

AsyncHttpClient client = asyncHttpClient();
// ResponseFilter triggers request replay to a different target host
ResponseFilter filter = response -> {
// Replays request to an unintended secondary host without updating target pointer
return new FilterContext.Builder(response).replayRequest(true).build();
};

Exploit: (Educational Purposes!)

An attacker leverages applications utilizing built-in failover patterns or custom ResponseFilters that replay requests. When the client invokes a failover path, the target request pointer fails to update alongside the current request. Because connection pool keys and authentication realms rely on stale pointers, subsequent requests containing sensitive session cookies or Authorization headers are routed to alternative hosts, disclosing credentials across trust boundaries.

Protection: from this CVE

Upgrade AsyncHttpClient to version 3.0.13 on the 3.x branch or version 2.16.1 on the 2.x branch. Avoid using custom ResponseFilters that replay requests to different hosts, and disable automatic request retries when handling sensitive credentials or working through proxies.

Impact

Exposure of sensitive authentication headers, credentials, and plaintext traffic to arbitrary secondary hosts, leading to cross-origin data leakage and unauthorized data access across distributed backend services.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top