HTTP Proxy Vulnerability in AsyncHttpClient Library by AsyncHttpClient
CVE-2026-107232
What is CVE-2026-107232?
The AsyncHttpClient library, widely used for executing HTTP requests in Java applications, contains a vulnerability that can lead to the exposure of sensitive authentication credentials. This flaw exists in versions prior to 3.0.12 on the 3.x branch and 2.16.1 on the 2.x branch. The issue arises from the improper inference of an HTTP proxy tunnel based solely on the last request method instead of the response from the CONNECT request. When a proxy connection is rejected, any redirect or authentication handlers may inadvertently write the original request and its authorization credentials onto the plaintext proxy connection, putting Basic credentials at risk of being directly recovered. Additionally, NTLM responses may be vulnerable to cracking or relaying, creating significant security implications for applications that rely on the library. It is essential for users to upgrade to the fixed versions to mitigate this risk.
Affected Version(s)
async-http-client >= 3.0.0, < 3.0.12 < 3.0.0, 3.0.12
async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1
