PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107232 AsyncHttpClient CVE debrief

The AsyncHttpClient library, used by Java applications for HTTP requests, had an issue where it could send origin credentials in cleartext to a proxy that rejects the CONNECT request. This happened because the client would infer the existence of an HTTP proxy tunnel from the last request method instead of the CONNECT result. As a result, after a proxy rejects CONNECT, redirect or authentication handlers could write an origin request and its Authorization credentials onto the still-plaintext proxy connection. Basic credentials could be directly recovered, while NTLM responses might be cracked or relayed. The issue is fixed in versions 3.0.12 and 2.16.1.

Vendor
AsyncHttpClient
Product
async-http-client
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders and security teams responsible for Java applications using the AsyncHttpClient library should assess their exposure and prioritize remediation. This includes reviewing application dependencies, identifying vulnerable versions, and upgrading to fixed versions. Additionally, they should ensure that proxy configurations are secure and that credentials are properly protected during transmission.

Why it matters

The vulnerability in AsyncHttpClient could lead to exposure of origin credentials, potentially allowing unauthorized access or lateral movement within networks. Defenders should prioritize verifying and remediating this vulnerability to protect against potential credential exposure and misuse.

  • Potential exposure of origin credentials to proxies that reject CONNECT requests
  • Possible recovery of basic credentials directly from cleartext transmissions
  • Potential cracking or relaying of NTLM responses
  • Need for verification of proxy configurations and credential security

Technical summary

The AsyncHttpClient library, used for HTTP requests in Java applications, had a vulnerability where it could send origin credentials in cleartext to a proxy that rejects the CONNECT request. This occurred because the client inferred the existence of an HTTP proxy tunnel from the last request method rather than the CONNECT result. After a proxy rejects CONNECT, redirect or authentication handlers could write an origin request and its Authorization credentials onto the still-plaintext proxy connection. Basic credentials could be directly recovered, while NTLM responses might be cracked or relayed. The issue is fixed in versions 3.0.12 and 2.16.1.

Defensive priority

Defenders should prioritize verifying if their applications use vulnerable versions of AsyncHttpClient and upgrading to fixed versions (3.0.12 or 2.16.1) as soon as possible. They should also review their proxy configurations and ensure that any credentials or sensitive data are properly secured during transmission.

Recommended defensive actions

  • Verify if applications use vulnerable versions of AsyncHttpClient
  • Upgrade to fixed versions (3.0.12 or 2.16.1) as soon as possible
  • Review proxy configurations to ensure proper security of credentials and sensitive data
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details about the vulnerability in AsyncHttpClient. The issue arises from the client's handling of HTTP proxy tunnels and CONNECT requests, leading to potential exposure of origin credentials. The fixes are available in versions 3.0.12 and 2.16.1.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107232 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107232

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107232 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107232

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • AsyncHttpClient: Origin credentials sent in cleartext to a proxy that rejects the CONNECT

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107232.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v9f2-7rw2-gr2x

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/3a625cb892233c0a6653ac68823a25ffbc80f393

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/a87e7b8c81a6f66a4ce23cd43097fbadd1c788ea

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.