Insufficiently Protected Credentials Affecting org.asynchttpclient:async-http-client package, versions [,2.16.1)[3.0.0.Beta1,3.0.12)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.27% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGASYNCHTTPCLIENT-19963948
  • published20 Sept 2026
  • disclosed17 Sept 2026
  • credithyperxpro

Introduced: 17 Sep 2026

NewCVE-2026-85720  (opens in a new tab)
CWE-319  (opens in a new tab)
CWE-522  (opens in a new tab)

How to fix?

Upgrade org.asynchttpclient:async-http-client to version 2.16.1, 3.0.12 or higher.

Overview

org.asynchttpclient:async-http-client is a maven plugin for the Async Http Client (AHC) classes.

Affected versions of this package are vulnerable to Insufficiently Protected Credentials via the newNettyRequest and writeRequest/sendRequestWithNewChannel paths in NettyRequestFactory and NettyRequestSender. An attacker can capture origin credentials by causing a request to an HTTPS origin to be sent through an HTTP proxy, where the client places preemptive Authorization headers on the plaintext CONNECT request. This leaks Basic, Digest, NTLM, SPNEGO, or Kerberos credentials to the proxy and any observer on the client-to-proxy hop, exposing secrets intended only for the origin server.

Workarounds

  • Do not use preemptive origin authentication together with an HTTP proxy; disable preemptive origin auth for proxied HTTPS requests so origin Authorization headers are not sent on the plaintext CONNECT to the proxy.
  • Reach the origin without a CONNECT proxy; route the request directly to the HTTPS origin so origin credentials are not exposed on the client-to-proxy hop.

CVSS Base Scores

version 4.0
version 3.1