Impact
AsyncHttpClient stores and forwards proxy credentials to the target server when a Java application uses an authenticated SOCKS proxy. The library attaches a Proxy‑Authorization header, or later forwards credentials through the existing SOCKS tunnel, without first confirming that the request is addressed to an HTTP proxy. Because the header is sent over plaintext HTTP, Basic, NTLM, Kerberos, and SPNEGO credentials can be read by the origin server. This results in a leak of authentication secrets that could be exploited to impersonate users or gain additional access. The weakness is associated with CWE‑319, CWE‑522, and CWE‑201.
Affected Systems
AsyncHttpClient from version 2.1.0 up to, but not including, 2.16.1, and from 3.0.0 up to, but not including, 3.0.12, are vulnerable. The fix is released in version 2.16.1 and 3.0.12. Any Java application that depends on AsyncHttpClient with an authenticated SOCKS proxy should check for and apply those patched versions. Applications that still use older libraries or no proxy are not affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact vulnerability, yet the EPSS score is below 1%, suggesting that exploitation is unlikely in the wild at present. The issue is not listed in the CISA KEV catalog. Attackers need control over a target or the network path to the origin server to read the tampered headers. In the pre‑emptive authentication flow, a malicious origin can simply inspect the plaintext request. In the non‑pre‑emptive flow, the origin can issue a 407 response and force the client to resend credentials through the SOCKS tunnel, again exposing them. Although exploitation requires specific conditions, the disclosure of credentials remains a serious risk for any system that relies on authenticated SOCKS proxies.
OpenCVE Enrichment