{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-107284","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2026-10-07T15:53:23.586Z","datePublished":"2026-10-07T21:27:03.257Z","dateUpdated":"2026-10-07T21:27:03.257Z"},"containers":{"cna":{"title":"AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-Accept check","problemTypes":[{"descriptions":[{"cweId":"CWE-345","lang":"en","description":"CWE-345: Insufficient Verification of Data Authenticity","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-670","lang":"en","description":"CWE-670: Always-Incorrect Control Flow Implementation","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}}],"references":[{"name":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rwhr-j9rv-85f8","tags":["x_refsource_CONFIRM"],"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rwhr-j9rv-85f8"},{"name":"https://github.com/AsyncHttpClient/async-http-client/commit/75a278550aa9a980009d022fb4e635f9c8738c03","tags":["x_refsource_MISC"],"url":"https://github.com/AsyncHttpClient/async-http-client/commit/75a278550aa9a980009d022fb4e635f9c8738c03"},{"name":"https://github.com/AsyncHttpClient/async-http-client/commit/ccdcaa627db6d96dcc42105212cb3ba5048bd7f9","tags":["x_refsource_MISC"],"url":"https://github.com/AsyncHttpClient/async-http-client/commit/ccdcaa627db6d96dcc42105212cb3ba5048bd7f9"},{"name":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","tags":["x_refsource_MISC"],"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"},{"name":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12","tags":["x_refsource_MISC"],"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12"}],"affected":[{"vendor":"AsyncHttpClient","product":"async-http-client","versions":[{"version":">= 3.0.0, < 3.0.12","status":"affected"},{"version":">= 2.0.0, < 2.16.1","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2026-10-07T21:27:03.257Z"},"descriptions":[{"lang":"en","value":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, WebSocketHandler.upgrade aborts a handshake whose Sec-WebSocket-Accept value is missing or invalid but continues into pipeline installation and onOpen delivery. Frames coalesced with the invalid 101 response can be decoded and delivered from a peer that did not prove the handshake, although the request future fails and the channel closes. This issue is fixed in versions 3.0.12 and 2.16.1."}],"source":{"advisory":"GHSA-rwhr-j9rv-85f8","discovery":"UNKNOWN"}}}}