2026-10-07 21:27CVE-2026-107284GitHub_M
PUBLISHED5.2CWE-345CWE-670

AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-Accept check

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, WebSocketHandler.upgrade aborts a handshake whose Sec-WebSocket-Accept value is missing or invalid but continues into pipeline installation and onOpen delivery. Frames coalesced with the invalid 101 response can be decoded and delivered from a peer that did not prove the handshake, although the request future fails and the channel closes. This issue is fixed in versions 3.0.12 and 2.16.1.

Problem type

Affected products

AsyncHttpClient

async-http-client

>= 3.0.0, < 3.0.12 - AFFECTED

>= 2.0.0, < 2.16.1 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-107284
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-107284",
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "dateUpdated": "2026-10-07T21:27:03.257Z",
    "dateReserved": "2026-10-07T15:53:23.586Z",
    "datePublished": "2026-10-07T21:27:03.257Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M",
        "dateUpdated": "2026-10-07T21:27:03.257Z"
      },
      "title": "AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-Accept check",
      "descriptions": [
        {
          "lang": "en",
          "value": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, WebSocketHandler.upgrade aborts a handshake whose Sec-WebSocket-Accept value is missing or invalid but continues into pipeline installation and onOpen delivery. Frames coalesced with the invalid 101 response can be decoded and delivered from a peer that did not prove the handshake, although the request future fails and the channel closes. This issue is fixed in versions 3.0.12 and 2.16.1."
        }
      ],
      "affected": [
        {
          "vendor": "AsyncHttpClient",
          "product": "async-http-client",
          "versions": [
            {
              "version": ">= 3.0.0, < 3.0.12",
              "status": "affected"
            },
            {
              "version": ">= 2.0.0, < 2.16.1",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-345: Insufficient Verification of Data Authenticity",
              "cweId": "CWE-345",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-670: Always-Incorrect Control Flow Implementation",
              "cweId": "CWE-670",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rwhr-j9rv-85f8",
          "name": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rwhr-j9rv-85f8",
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/75a278550aa9a980009d022fb4e635f9c8738c03",
          "name": "https://github.com/AsyncHttpClient/async-http-client/commit/75a278550aa9a980009d022fb4e635f9c8738c03",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/ccdcaa627db6d96dcc42105212cb3ba5048bd7f9",
          "name": "https://github.com/AsyncHttpClient/async-http-client/commit/ccdcaa627db6d96dcc42105212cb3ba5048bd7f9",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1",
          "name": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12",
          "name": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12",
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW"
          }
        }
      ]
    }
  }
}