CVE-2026-107285
Received Received - Intake

WebSocket Proxy Authentication Bypass in AsyncHttpClient

Vulnerability report for CVE-2026-107285, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
AsyncHttpClient async-http-client >= 3.0.0, <3.0.12
AsyncHttpClient async-http-client >= 2.0.0, < 2.16.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The AsyncHttpClient (AHC) library before versions 3.0.12 and 2.16.1 has a flaw where proxied WebSocket (ws) requests are not properly secured. When a ws request is tunneled through a proxy using CONNECT, the library attaches proxy authentication and an absolute-form target based on whether the URI is marked as secure. Since ws is not considered secure, the WebSocket upgrade request sent to the origin includes the proxy's Proxy-Authorization header. This exposes basic credentials directly and allows Digest responses to be replayed or cracked offline.

Detection Guidance

Check the version of AsyncHttpClient in use. If it is below 3.0.12 or 2.16.1, the system is vulnerable. Commands like 'mvn dependency:tree' for Maven or 'gradle dependencies' for Gradle can help identify the library version.

Impact Analysis

This vulnerability could allow attackers to intercept and misuse proxy authentication credentials. Basic credentials may be exposed directly, while Digest credentials could be replayed or cracked offline. This could lead to unauthorized access to resources or data if the proxy credentials grant access to sensitive systems.

Compliance Impact

This vulnerability exposes proxy authentication credentials, including Basic and Digest credentials, which could lead to unauthorized access to sensitive data. This may violate GDPR's data protection principles and HIPAA's security requirements for safeguarding protected health information.

Mitigation Strategies

Upgrade AsyncHttpClient to version 3.0.12 or 2.16.1 or later. Remove or disable any affected versions if immediate upgrade is not possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107285. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart