PatchSiren cyber security CVE debrief
CVE-2026-107232 AsyncHttpClient CVE debrief
The AsyncHttpClient library, used by Java applications for HTTP requests, had an issue where it could send origin credentials in cleartext to a proxy that rejects the CONNECT request. This happened because the client would infer the existence of an HTTP proxy tunnel from the last request method instead of the CONNECT result. As a result, after a proxy rejects CONNECT, redirect or authentication handlers could write an origin request and its Authorization credentials onto the still-plaintext proxy connection. Basic credentials could be directly recovered, while NTLM responses might be cracked or relayed. The issue is fixed in versions 3.0.12 and 2.16.1.
- Vendor
- AsyncHttpClient
- Product
- async-http-client
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders and security teams responsible for Java applications using the AsyncHttpClient library should assess their exposure and prioritize remediation. This includes reviewing application dependencies, identifying vulnerable versions, and upgrading to fixed versions. Additionally, they should ensure that proxy configurations are secure and that credentials are properly protected during transmission.
Why it matters
The vulnerability in AsyncHttpClient could lead to exposure of origin credentials, potentially allowing unauthorized access or lateral movement within networks. Defenders should prioritize verifying and remediating this vulnerability to protect against potential credential exposure and misuse.
- Potential exposure of origin credentials to proxies that reject CONNECT requests
- Possible recovery of basic credentials directly from cleartext transmissions
- Potential cracking or relaying of NTLM responses
- Need for verification of proxy configurations and credential security
Technical summary
The AsyncHttpClient library, used for HTTP requests in Java applications, had a vulnerability where it could send origin credentials in cleartext to a proxy that rejects the CONNECT request. This occurred because the client inferred the existence of an HTTP proxy tunnel from the last request method rather than the CONNECT result. After a proxy rejects CONNECT, redirect or authentication handlers could write an origin request and its Authorization credentials onto the still-plaintext proxy connection. Basic credentials could be directly recovered, while NTLM responses might be cracked or relayed. The issue is fixed in versions 3.0.12 and 2.16.1.
Defensive priority
Defenders should prioritize verifying if their applications use vulnerable versions of AsyncHttpClient and upgrading to fixed versions (3.0.12 or 2.16.1) as soon as possible. They should also review their proxy configurations and ensure that any credentials or sensitive data are properly secured during transmission.
Recommended defensive actions
- Verify if applications use vulnerable versions of AsyncHttpClient
- Upgrade to fixed versions (3.0.12 or 2.16.1) as soon as possible
- Review proxy configurations to ensure proper security of credentials and sensitive data
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details about the vulnerability in AsyncHttpClient. The issue arises from the client's handling of HTTP proxy tunnels and CONNECT requests, leading to potential exposure of origin credentials. The fixes are available in versions 3.0.12 and 2.16.1.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107232 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107232
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107232 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107232
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
AsyncHttpClient: Origin credentials sent in cleartext to a proxy that rejects the CONNECT
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107232.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v9f2-7rw2-gr2x
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/commit/3a625cb892233c0a6653ac68823a25ffbc80f393
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/commit/a87e7b8c81a6f66a4ce23cd43097fbadd1c788ea
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.