CVE-2026-107232 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.
Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 on 3.x and 2.16.1 on 2.x, the client infers that an HTTP proxy tunnel exists from the last request method rather than the CONNECT result. After a proxy rejects CONNECT, redirect or authentication handlers can write an origin request and its Authorization credentials onto the still-plaintext proxy connection. Basic credentials can be recovered directly, while NTLM responses may be cracked or relayed. This issue is fixed in versions 3.0.12 and 2.16.1.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
High
Confidentiality
I
None
Integrity
A
None
Availability
References
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/commit/3a625cb892233c0a6653ac68823a25ffbc80f393
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/commit/a87e7b8c81a6f66a4ce23cd43097fbadd1c788ea
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v9f2-7rw2-gr2x
Related threats
same CWE or vendorCVE-2026-107715 — The Mechanize library is used for automating interaction with websites.
CVE-2026-107715 · 2h ago
CVE-2026-107714 — The Mechanize library is used for automating interaction with websites.
CVE-2026-107714 · 2h ago
CVE-2026-107399 — The Mechanize library is used for automating interaction with websites.
CVE-2026-107399 · 2h ago
CVE-2026-107336 — Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive r…
CVE-2026-107336 · 6h ago
CVE-2026-105833 — EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account sc…
CVE-2026-105833 · 9h ago
CVE-2026-104704 — Progressive Robot hMailServer 6.0.0 through 6.3.5 does not enforce TLS for outbound SMTP delivery to a mail exchanger whose DNSSEC-validated TLSA r…
CVE-2026-104704 · 13h ago