Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the proxy's credentials to the origin because NettyRequestFactory and NettyRequestSender attach Proxy-Authorization without confirming that the request is being sent to an HTTP proxy. With preemptive proxy authentication, the header is attached to a plaintext HTTP request, exposing credentials such as directly reversible Basic credentials to the origin. With the default non-preemptive flow, a hostile origin can return a 407 response and ProxyUnauthorized407Interceptor sends the proxy credentials through the existing SOCKS tunnel, including NTLM, Kerberos, and SPNEGO credentials. Releases before 2.1.0 lack SOCKS proxy support. This issue is fixed in versions 2.16.1 and 3.0.12.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Credential Disclosure to Origin Server
Action: Immediate Patch
AI Analysis

Impact

AsyncHttpClient stores and forwards proxy credentials to the target server when a Java application uses an authenticated SOCKS proxy. The library attaches a Proxy‑Authorization header, or later forwards credentials through the existing SOCKS tunnel, without first confirming that the request is addressed to an HTTP proxy. Because the header is sent over plaintext HTTP, Basic, NTLM, Kerberos, and SPNEGO credentials can be read by the origin server. This results in a leak of authentication secrets that could be exploited to impersonate users or gain additional access. The weakness is associated with CWE‑319, CWE‑522, and CWE‑201.

Affected Systems

AsyncHttpClient from version 2.1.0 up to, but not including, 2.16.1, and from 3.0.0 up to, but not including, 3.0.12, are vulnerable. The fix is released in version 2.16.1 and 3.0.12. Any Java application that depends on AsyncHttpClient with an authenticated SOCKS proxy should check for and apply those patched versions. Applications that still use older libraries or no proxy are not affected.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact vulnerability, yet the EPSS score is below 1%, suggesting that exploitation is unlikely in the wild at present. The issue is not listed in the CISA KEV catalog. Attackers need control over a target or the network path to the origin server to read the tampered headers. In the pre‑emptive authentication flow, a malicious origin can simply inspect the plaintext request. In the non‑pre‑emptive flow, the origin can issue a 407 response and force the client to resend credentials through the SOCKS tunnel, again exposing them. Although exploitation requires specific conditions, the disclosure of credentials remains a serious risk for any system that relies on authenticated SOCKS proxies.

Generated by OpenCVE AI on October 1, 2026 at 20:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AsyncHttpClient to version 2.16.1 or later, or to 3.0.12 or later, which contain the fix for this issue.
  • Verify that all build systems and dependency managers resolve to the patched version and remove any older transitive dependencies.
  • If an immediate upgrade is not possible, avoid using authenticated SOCKS proxies or disable preemptive proxy authentication until a patch is applied.

Generated by OpenCVE AI on October 1, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-201
References
Metrics threat_severity

None

threat_severity

Important


Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Asynchttpclient Project
Asynchttpclient Project async-http-client
Vendors & Products Asynchttpclient Project
Asynchttpclient Project async-http-client

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the proxy's credentials to the origin because NettyRequestFactory and NettyRequestSender attach Proxy-Authorization without confirming that the request is being sent to an HTTP proxy. With preemptive proxy authentication, the header is attached to a plaintext HTTP request, exposing credentials such as directly reversible Basic credentials to the origin. With the default non-preemptive flow, a hostile origin can return a 407 response and ProxyUnauthorized407Interceptor sends the proxy credentials through the existing SOCKS tunnel, including NTLM, Kerberos, and SPNEGO credentials. Releases before 2.1.0 lack SOCKS proxy support. This issue is fixed in versions 2.16.1 and 3.0.12.
Title AsyncHttpClient: SOCKS proxy credentials sent to the origin server over plaintext HTTP
Weaknesses CWE-319
CWE-522
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Asynchttpclient Project Async-http-client
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T14:45:01.238Z

Reserved: 2026-09-04T14:45:10.648Z

Link: CVE-2026-85719

cve-icon Vulnrichment

Updated: 2026-09-18T14:39:47.303Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:18:16.273

Modified: 2026-09-24T21:16:28.120

Link: CVE-2026-85719

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-17T15:52:16Z

Links: CVE-2026-85719 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T20:45:12Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data

  • CWE-319

    Cleartext Transmission of Sensitive Information

  • CWE-522

    Insufficiently Protected Credentials