Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 on 3.x and 2.16.1 on 2.x, the client infers that an HTTP proxy tunnel exists from the last request method rather than the CONNECT result. After a proxy rejects CONNECT, redirect or authentication handlers can write an origin request and its Authorization credentials onto the still-plaintext proxy connection. Basic credentials can be recovered directly, while NTLM responses may be cracked or relayed. This issue is fixed in versions 3.0.12 and 2.16.1.
Published: 2026-10-07
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Credentials Exposure
Action: Patch
AI Analysis

Impact

AsyncHttpClient misinterprets connector status for HTTP proxies, assuming a tunnel exists based on the last request method rather than the success of the CONNECT operation. When a CONNECT is rejected, the library still transmits the origin request and any attached Authorization header downstream over the still-plaintext proxy connection. As a result, Basic credentials can be read directly, and NTLM authentication exchanges may be cracked or relayed. This flaw enables credential theft for the Java application.

Affected Systems

The vulnerability affects the AsyncHttpClient library, known as AsyncHttpClient:async-http-client. Any Java application that relies on versions earlier than 3.0.12 on the 3.x branch or earlier than 2.16.1 on the 2.x branch is susceptible. The affected component is the proxy tunneling logic that incorrectly infers tunnel existence from the request method rather than the CONNECT outcome.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, the EPSS value is unavailable, and the vulnerability is not listed in CISA KEV. The likely attack vector is a network-based proxy connection; an attacker controlling or monitoring an HTTP proxy that rejects CONNECT requests can exploit the flaw by sending arbitrary requests. Successful exploitation yields unauthorized credential theft, potentially enabling unauthorized access to protected resources or privileged accounts.

Generated by OpenCVE AI on October 7, 2026 at 23:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AsyncHttpClient to version 3.0.12 (3.x) or 2.16.1 (2.x) or newer
  • Configure the application to validate CONNECT responses before sending any origin requests and to use only trusted, authenticated proxies
  • If upgrading is not immediately possible, disable proxy tunneling or enforce TLS for proxy connections to prevent credentials from being transmitted in cleartext

Generated by OpenCVE AI on October 7, 2026 at 23:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 on 3.x and 2.16.1 on 2.x, the client infers that an HTTP proxy tunnel exists from the last request method rather than the CONNECT result. After a proxy rejects CONNECT, redirect or authentication handlers can write an origin request and its Authorization credentials onto the still-plaintext proxy connection. Basic credentials can be recovered directly, while NTLM responses may be cracked or relayed. This issue is fixed in versions 3.0.12 and 2.16.1.
Title AsyncHttpClient: Origin credentials sent in cleartext to a proxy that rejects the CONNECT
Weaknesses CWE-319
CWE-441
CWE-522
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T21:09:03.284Z

Reserved: 2026-10-07T14:34:14.817Z

Link: CVE-2026-107232

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T22:17:03.497

Modified: 2026-10-07T22:17:03.497

Link: CVE-2026-107232

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:15:08Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information

  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')

  • CWE-522

    Insufficiently Protected Credentials