CVE-2026-45300Disclosure(asynchttpclient_project / async-http-client)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch asynchttpclient_project async-http-client systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin, the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip the `Cookie` header, causing session cookies and other sensitive cookie values to be sent to attacker-controlled servers. Versions 2.15.0 and 3.0.10 patch the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • async-http-client

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-06); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
async-http-client

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-18: 1Mentions · 2026-06-06: 2Mentions · 2026-07-30: 1Patch / Workaround · 2026-07-30: 1Technical Details · 2026-05-18: 1Technical Details · 2026-06-06: 1Technical Details · 2026-07-30: 105-1806-0607-30
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-181
Disclosure1
2026-06-062
Disclosure1General1
2026-07-301
Patch1
Full discourse4 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-45300 (CVSS 7.4) AsyncHttpClient (AHC) library leaks Cookie headers to cross-origin redirects, exposing session tokens to attacker-controlled servers. Affected: v2.x <2.15.0, v3.x <3.0.10 ✅ Patch now! #CVE #Vulnerability #PatchNow https://t.co/WQUj78TK8G

    Post summary

    The tweet announces a high‑severity CVE involving AsyncHttpClient leaking Cookie headers; affected versions are listed and a patch is available.

    0000068
    98 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-45300 The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior… https://www.cve.org/CVERecord?id=CVE-2026-45300

    Post summary

    A brief CVE mention with no additional technical or exploit details provided.

    00000150
    57.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-45300 Cookie Header Leakage to Cross-Origin Redirect Targets in AsyncHttpClient https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45300

    Post summary

    The text announces CVE‑2026‑45300, highlighting that AsyncHttpClient leaks cookie headers to cross‑origin redirect targets.

    0000040
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 async-http-client, Information Disclosure, #CVE-2026-45300 (Medium) https://dailycve.com/async-http-client-information-disclosure-cve-2026-45300-medium/

    Post summary

    The article announces a medium‑severity Information Disclosure vulnerability (CVE-2026-45300) in async-http-client; however, it provides no PoC, exploit details, or mitigation guidance.

    0000050
    206 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appasynchttpclient_projectasync-http-client---

Explore more