Credential Exposure in AsyncHttpClient Library via Misconfigured HTTP Proxies
CVE-2026-85720

5.9MEDIUM

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-85720?

The AsyncHttpClient library has a vulnerability that allows sensitive credentials to be exposed during the use of HTTP proxies to access HTTPS origins. Specifically, when requests are made through an HTTP proxy, the Authorization headers can inadvertently be attached to plaintext CONNECT requests before a secure TLS tunnel is established. This oversight permits the visibility of Basic or Digest credentials, as well as NTLM, Kerberos, or SPNEGO tokens to both the proxy server and any observers on the communication path. Although the tunneled requests still carry the proper Authorization headers to the intended origin, the exposure of sensitive information in transit represents a significant security risk that has been addressed in updates 2.16.1 and 3.0.12.

Affected Version(s)

async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1

async-http-client >= 3.0.0, < 3.0.12 < 3.0.0, 3.0.12

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.