PT-2026-94395 · Unknown · Async Http Client

·

CVE-2026-85720

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AsyncHttpClient versions 2.0.0 through 2.16.0 AsyncHttpClient versions 3.0.0 through 3.0.11
Description When using an HTTP proxy to reach an HTTPS origin, the library may expose preemptive origin credentials. This occurs because NettyRequestFactory and the sendRequestWithNewChannel function in NettyRequestSender attach the Authorization header to the plaintext CONNECT request before the TLS tunnel is established. Consequently, Basic or Digest credentials, as well as per-connection NTLM, Kerberos, or SPNEGO tokens intended for the origin, are transmitted in cleartext and are visible to the proxy and any observers on the network hop between the client and the proxy.
Recommendations Update to version 2.16.1 or later. Update to version 3.0.12 or later. As a temporary workaround, avoid using preemptive origin authentication when using an HTTP proxy, or connect to the origin without using a CONNECT proxy.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85720
GHSA-XR57-GCX8-52HF

Affected Products

Async Http Client