Origin Validation Error Affecting org.asynchttpclient:async-http-client package, versions [,2.14.5)[3.0.0.Beta1,3.0.9)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.07% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGASYNCHTTPCLIENT-16032254
  • published14 Apr 2026
  • disclosed14 Apr 2026
  • creditUnknown

Introduced: 14 Apr 2026

CVE-2026-40490  (opens in a new tab)
CWE-346  (opens in a new tab)

How to fix?

Upgrade org.asynchttpclient:async-http-client to version 2.14.5, 3.0.9 or higher.

Overview

org.asynchttpclient:async-http-client is a maven plugin for the Async Http Client (AHC) classes.

Affected versions of this package are vulnerable to Origin Validation Error in the Redirect30xInterceptor class. An attacker in control of a cross-origin redirect target via a different exploit such as open redirect or DNS rebinding, or who is in a MitM position on HTTP connections, can leak Authorization and Proxy-Authorization headers. This is only exploitable if redirect following is enabled - i.e. followRedirect(true).

Workaround

This vulnerability can be avoided by setting followRedirect(false). Setting stripAuthorizationOnRedirect(true) only prevents this exploit if Realm-based authentication is NOT in use.

CVSS Base Scores

version 4.0
version 3.1