CVE-2026-107285
AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunnel
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1.
| CWE | CWE-319 CWE-522 |
| Vendor | asynchttpclient |
| Product | async-http-client |
| Published | Oct 7, 2026 |
Get instant alerts for asynchttpclient async-http-client
Be the first to know when new medium vulnerabilities affecting asynchttpclient async-http-client are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N