HTTP Proxy Vulnerability in AsyncHttpClient Library by AsyncHttpClient
CVE-2026-107232

7.5HIGH

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-107232?

The AsyncHttpClient library, widely used for executing HTTP requests in Java applications, contains a vulnerability that can lead to the exposure of sensitive authentication credentials. This flaw exists in versions prior to 3.0.12 on the 3.x branch and 2.16.1 on the 2.x branch. The issue arises from the improper inference of an HTTP proxy tunnel based solely on the last request method instead of the response from the CONNECT request. When a proxy connection is rejected, any redirect or authentication handlers may inadvertently write the original request and its authorization credentials onto the plaintext proxy connection, putting Basic credentials at risk of being directly recovered. Additionally, NTLM responses may be vulnerable to cracking or relaying, creating significant security implications for applications that rely on the library. It is essential for users to upgrade to the fixed versions to mitigate this risk.

Affected Version(s)

async-http-client >= 3.0.0, < 3.0.12 < 3.0.0, 3.0.12

async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.