CVE-2026-45300Asynchttpclient_project · Async-http-client
Vulnerability data via NVD (ingested)
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin, the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip the `Cookie` header, causing session cookies and other sensitive cookie values to be sent to attacker-controlled servers. Versions 2.15.0 and 3.0.10 patch the issue.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-45300product:"Asynchttpclient Project Async-http-client"http.html:"Async-http-client"More intel sources (5)
vuln:CVE-2026-45300vulnerabilities.cve_id: CVE-2026-45300CVE-2026-45300CVE-2026-45300"CVE-2026-45300" exploit -site:nvd.nist.gov