PT-2026-94385 · Unknown · Async Http Client
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AsyncHttpClient versions 2.1.0 through 2.16.0
AsyncHttpClient versions 3.0.1 through 3.0.11
Description
Requests using an authenticated SOCKS proxy can expose proxy credentials to the origin server. This occurs because
NettyRequestFactory and NettyRequestSender attach the Proxy-Authorization header without verifying if the request is being sent to an HTTP proxy. In preemptive proxy authentication, the header is attached to a plaintext HTTP request, exposing Basic credentials. In the default non-preemptive flow, a hostile origin can trigger a 407 response, causing ProxyUnauthorized407Interceptor to send credentials, including NTLM, Kerberos, and SPNEGO, through the SOCKS tunnel.Recommendations
Update to version 2.16.1.
Update to version 3.0.12.
Exploit
Fix
Insufficiently Protected Credentials
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Async Http Client