Impact
The vulnerable version of AsyncHttpClient treats WebSocket upgrades as non‑secure and forwards the Proxy‑Authorization header unchanged through the CONNECT tunnel. This allows anyone who can observe or tamper with the proxied WebSocket request to recover Basic authentication credentials directly or to replay or crack Digest authentication responses, thereby compromising the confidentiality of proxy credentials used by the application.
Affected Systems
Java applications that employ AsyncHttpClient async-http-client before release 2.16.1 or 3.0.12 and perform WebSocket requests through an HTTP proxy are affected. The issue is present in all earlier releases and has been fixed in the mentioned versions.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker can observe or inject traffic for a proxied WebSocket request; when they obtain the Authorization header they can directly consume the credentials or use offline analysis to crack or reuse them.
OpenCVE Enrichment
Github GHSA