2026-10-07 21:28CVE-2026-107285GitHub_M
PUBLISHED5.2CWE-319CWE-522

AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunnel

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1.

Problem type

Affected products

AsyncHttpClient

async-http-client

>= 3.0.0, <3.0.12 - AFFECTED

>= 2.0.0, < 2.16.1 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-107285
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-107285",
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "dateUpdated": "2026-10-07T21:28:34.620Z",
    "dateReserved": "2026-10-07T15:53:23.586Z",
    "datePublished": "2026-10-07T21:28:34.620Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M",
        "dateUpdated": "2026-10-07T21:28:34.620Z"
      },
      "title": "AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunnel",
      "descriptions": [
        {
          "lang": "en",
          "value": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1."
        }
      ],
      "affected": [
        {
          "vendor": "AsyncHttpClient",
          "product": "async-http-client",
          "versions": [
            {
              "version": ">= 3.0.0, <3.0.12",
              "status": "affected"
            },
            {
              "version": ">= 2.0.0, < 2.16.1",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-319: Cleartext Transmission of Sensitive Information",
              "cweId": "CWE-319",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-522: Insufficiently Protected Credentials",
              "cweId": "CWE-522",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-3wp9-xfwm-rjjf",
          "name": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-3wp9-xfwm-rjjf",
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/6e9cb75a9b7259353f983fc90ca28b1da3742e18",
          "name": "https://github.com/AsyncHttpClient/async-http-client/commit/6e9cb75a9b7259353f983fc90ca28b1da3742e18",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/c4feab0f7f86d61505a48e40d383c8a375a22e18",
          "name": "https://github.com/AsyncHttpClient/async-http-client/commit/c4feab0f7f86d61505a48e40d383c8a375a22e18",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1",
          "name": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12",
          "name": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12",
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM"
          }
        }
      ]
    }
  }
}