CVE-2026-107285: fallo de gravedad media en AsyncHttpClient async-http-client
AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunnel
Publicada el
10Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.9
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Productos afectados
AsyncHttpClient · async-http-clientCVEs relacionadas — AsyncHttpClient async-http-client
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-53990CRITICALAsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`sEPSS 0.6%CVE-2026-85721HIGHAsyncHttpClient: Unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of serviceEPSS 0.6%CVE-2026-85718MEDIUMAsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial of serviceEPSS 0.5%CVE-2026-85717MEDIUMAsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect targetEPSS 0.5%CVE-2026-40490MEDIUMAsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirectsEPSS 0.5%CVE-2026-45300HIGHasync-http-client: Cookie header not stripped on cross-origin redirectEPSS 0.5%
Referencias
https://github.com/AsyncHttpClient/async-http-client/commit/6e9cb75a9b7259353f983fc90ca28b1da3742e18https://github.com/AsyncHttpClient/async-http-client/commit/c4feab0f7f86d61505a48e40d383c8a375a22e18https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-3wp9-xfwm-rjjf