Credential Exposure in AsyncHttpClient Library via Misconfigured HTTP Proxies
CVE-2026-85720
What is CVE-2026-85720?
The AsyncHttpClient library has a vulnerability that allows sensitive credentials to be exposed during the use of HTTP proxies to access HTTPS origins. Specifically, when requests are made through an HTTP proxy, the Authorization headers can inadvertently be attached to plaintext CONNECT requests before a secure TLS tunnel is established. This oversight permits the visibility of Basic or Digest credentials, as well as NTLM, Kerberos, or SPNEGO tokens to both the proxy server and any observers on the communication path. Although the tunneled requests still carry the proper Authorization headers to the intended origin, the exposure of sensitive information in transit represents a significant security risk that has been addressed in updates 2.16.1 and 3.0.12.
Affected Version(s)
async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1
async-http-client >= 3.0.0, < 3.0.12 < 3.0.0, 3.0.12
