Impact
AsyncHttpClient misinterprets connector status for HTTP proxies, assuming a tunnel exists based on the last request method rather than the success of the CONNECT operation. When a CONNECT is rejected, the library still transmits the origin request and any attached Authorization header downstream over the still-plaintext proxy connection. As a result, Basic credentials can be read directly, and NTLM authentication exchanges may be cracked or relayed. This flaw enables credential theft for the Java application.
Affected Systems
The vulnerability affects the AsyncHttpClient library, known as AsyncHttpClient:async-http-client. Any Java application that relies on versions earlier than 3.0.12 on the 3.x branch or earlier than 2.16.1 on the 2.x branch is susceptible. The affected component is the proxy tunneling logic that incorrectly infers tunnel existence from the request method rather than the CONNECT outcome.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, the EPSS value is unavailable, and the vulnerability is not listed in CISA KEV. The likely attack vector is a network-based proxy connection; an attacker controlling or monitoring an HTTP proxy that rejects CONNECT requests can exploit the flaw by sending arbitrary requests. Successful exploitation yields unauthorized credential theft, potentially enabling unauthorized access to protected resources or privileged accounts.
OpenCVE Enrichment