Impact
The AsyncHttpClient library, in versions 2.0.0 through 2.16.1 and 3.0 up to 3.0.12, attaches origin Authorization headers to the plaintext CONNECT request used to establish an HTTPS tunnel. This makes Basic, Digest, NTLM, Kerberos, or SPNEGO tokens intended for the remote HTTPS server visible on the client‑to‑proxy hop. An attacker who can observe or control the proxy can capture these credentials, which can then be reused against the target origin. The flaw constitutes the cleartext transmission of sensitive information and the use of insufficiently protected credentials, aligning with CWE‑319 and CWE‑522.
Affected Systems
The affected product is AsyncHttpClient (AHC), part of the AsyncHttpClient:async-http-client library. All releases from 2.0.0 up to (but excluding) 2.16.1, and from the 3.0 series up to (but excluding) 3.0.12 are vulnerable. The issue is resolved in library version 2.16.1 and 3.0.12 or newer; deployments should verify that the library is at least that version.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity vulnerability, yet the EPSS score is below 1 %, implying a low probability of active exploitation. The vulnerability is not listed in CISA's KEV catalog. Exfiltration of credentials requires an attacker to observe or influence the traffic between the client and the proxy, as the flaw is triggered whenever an HTTPS request is routed through a proxy. No additional privileges are required beyond proxy trust; the flaw is exercised immediately when the library sends an HTTPS request via a proxy, causing the library to forward the origin Authorization header in the CONNECT request before the TLS tunnel is established. The fix in 2.16.1 / 3.0.12 stops this behavior by preventing the library from attaching origin credentials to the CONNECT request.
OpenCVE Enrichment
Github GHSA