Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1.
Published: 2026-10-07
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Exposure of proxy credentials via CONNECT tunnel
Action: Patch
AI Analysis

Impact

The vulnerable version of AsyncHttpClient treats WebSocket upgrades as non‑secure and forwards the Proxy‑Authorization header unchanged through the CONNECT tunnel. This allows anyone who can observe or tamper with the proxied WebSocket request to recover Basic authentication credentials directly or to replay or crack Digest authentication responses, thereby compromising the confidentiality of proxy credentials used by the application.

Affected Systems

Java applications that employ AsyncHttpClient async-http-client before release 2.16.1 or 3.0.12 and perform WebSocket requests through an HTTP proxy are affected. The issue is present in all earlier releases and has been fixed in the mentioned versions.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker can observe or inject traffic for a proxied WebSocket request; when they obtain the Authorization header they can directly consume the credentials or use offline analysis to crack or reuse them.

Generated by OpenCVE AI on October 7, 2026 at 22:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the AsyncHttpClient library to version 3.0.12 or 2.16.1 or later, where the Proxy‑Authorization header is omitted from the CONNECT tunnel for WebSocket requests.
  • If an immediate upgrade is not possible, temporarily disable proxy authentication for WebSocket connections or enforce end‑to‑end TLS to prevent the header from being exposed.
  • After the upgrade or interim mitigations, scan the application code for older AsyncHttpClient imports, review dependency trees, and confirm that no vulnerable version is present in production deployments.

Generated by OpenCVE AI on October 7, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-3wp9-xfwm-rjjf AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunnel
History

Wed, 07 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1.
Title AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunnel
Weaknesses CWE-319
CWE-522
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T17:57:33.271Z

Reserved: 2026-10-07T15:53:23.586Z

Link: CVE-2026-107285

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T22:17:04.637

Modified: 2026-10-08T18:17:16.070

Link: CVE-2026-107285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:00:15Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information

  • CWE-522

    Insufficiently Protected Credentials