Impact
The AsyncHttpClient library contains a flaw where a cross-host request replay can leave the target request’s proxy context pointing at the original origin. As a result, the replayed request may transmit the original host’s path, Host header, authorization credentials, or even plaintext data to the new host. This can expose sensitive credentials and potentially other confidential information to an unintended destination. The weakness is classified as improper authentication handling (CWE-319, CWE-441, CWE-522).
Affected Systems
Applications that use AsyncHttpClient versions earlier than 3.0.13 and 2.16.1 are impacted. Any Java application that incorporates the library without updating to the patched releases may inadvertently send requests and credentials to third‑party hosts during retry or failover paths.
Risk and Exploitability
The vulnerability receives a CVSS score of 9.4, indicating a very high severity. The EPSS score is not available, so the current exploitation probability is unknown, but the risk is still significant due to the high impact. Because the flaw can be triggered during response filter failover or retry paths, a threat actor controlling a target host or the application network could coerce the victim application into sending credentials to the malicious server. The CVE is not listed in the CISA KEV catalog, but administrators should treat it as a critical exposure while a fix is not applied.
OpenCVE Enrichment
Github GHSA