Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose preemptive origin credentials because NettyRequestFactory and NettyRequestSender.sendRequestWithNewChannel attach Authorization to the plaintext CONNECT request before the TLS tunnel exists. Basic or Digest credentials and per-connection NTLM, Kerberos, or SPNEGO tokens intended for the origin are therefore visible to the proxy and to observers on the client-to-proxy hop. The tunneled request still receives origin Authorization after the tunnel is established, while Proxy-Authorization remains on CONNECT for its intended proxy recipient. This issue is fixed in versions 2.16.1 and 3.0.12.
Published: 2026-09-17
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unencrypted credentials are sent to a proxy during the CONNECT phase
Action: Immediate Patch
AI Analysis

Impact

The AsyncHttpClient library, in versions 2.0.0 through 2.16.1 and 3.0 up to 3.0.12, attaches origin Authorization headers to the plaintext CONNECT request used to establish an HTTPS tunnel. This makes Basic, Digest, NTLM, Kerberos, or SPNEGO tokens intended for the remote HTTPS server visible on the client‑to‑proxy hop. An attacker who can observe or control the proxy can capture these credentials, which can then be reused against the target origin. The flaw constitutes the cleartext transmission of sensitive information and the use of insufficiently protected credentials, aligning with CWE‑319 and CWE‑522.

Affected Systems

The affected product is AsyncHttpClient (AHC), part of the AsyncHttpClient:async-http-client library. All releases from 2.0.0 up to (but excluding) 2.16.1, and from the 3.0 series up to (but excluding) 3.0.12 are vulnerable. The issue is resolved in library version 2.16.1 and 3.0.12 or newer; deployments should verify that the library is at least that version.

Risk and Exploitability

The CVSS score of 5.9 indicates a medium severity vulnerability, yet the EPSS score is below 1 %, implying a low probability of active exploitation. The vulnerability is not listed in CISA's KEV catalog. Exfiltration of credentials requires an attacker to observe or influence the traffic between the client and the proxy, as the flaw is triggered whenever an HTTPS request is routed through a proxy. No additional privileges are required beyond proxy trust; the flaw is exercised immediately when the library sends an HTTPS request via a proxy, causing the library to forward the origin Authorization header in the CONNECT request before the TLS tunnel is established. The fix in 2.16.1 / 3.0.12 stops this behavior by preventing the library from attaching origin credentials to the CONNECT request.

Generated by OpenCVE AI on September 20, 2026 at 04:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AsyncHttpClient to version 2.16.1 or later (for the 3.0 series 3.0.12 or newer).
  • If an upgrade cannot be performed immediately, reconfigure the library or application to avoid routing HTTPS requests through untrusted proxies, or ensure that any proxy used does not forward or store origin Authorization headers.
  • Audit and harden proxy infrastructure to enforce strict handling of Authorization headers, ensuring that only proxy credentials are transmitted and origin credentials remain protected.

Generated by OpenCVE AI on September 20, 2026 at 04:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xr57-gcx8-52hf AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request
History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Asynchttpclient Project
Asynchttpclient Project async-http-client
Vendors & Products Asynchttpclient Project
Asynchttpclient Project async-http-client

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose preemptive origin credentials because NettyRequestFactory and NettyRequestSender.sendRequestWithNewChannel attach Authorization to the plaintext CONNECT request before the TLS tunnel exists. Basic or Digest credentials and per-connection NTLM, Kerberos, or SPNEGO tokens intended for the origin are therefore visible to the proxy and to observers on the client-to-proxy hop. The tunneled request still receives origin Authorization after the tunnel is established, while Proxy-Authorization remains on CONNECT for its intended proxy recipient. This issue is fixed in versions 2.16.1 and 3.0.12.
Title AsyncHttpClient: Origin credentials sent to the proxy on the plaintext CONNECT request
Weaknesses CWE-319
CWE-522
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Asynchttpclient Project Async-http-client
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:52:24.486Z

Reserved: 2026-09-04T14:45:10.648Z

Link: CVE-2026-85720

cve-icon Vulnrichment

Updated: 2026-09-21T20:52:19.311Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T17:16:51.200

Modified: 2026-09-24T21:16:28.120

Link: CVE-2026-85720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:15:17Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information

  • CWE-522

    Insufficiently Protected Credentials