{"id":"GHSA-3wp9-xfwm-rjjf","summary":"AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunnel","details":"### Impact\nWhen a ws:// request is routed through an HTTP proxy with proxy authentication configured, the client tunnels the connection with an HTTP CONNECT, the same as it does for https://. Once the tunnel is open, the WebSocket upgrade request that follows is sent through the tunnel directly to the origin server, not to the proxy. The proxy-auth gate and the companion request-target selection keyed only on whether the URI was secured, which is false for ws://, so the tunnelled upgrade request incorrectly carried the proxy's Proxy-Authorization header and an absolute-form request target meant for the proxy. Any origin server reached over a proxied ws:// connection, or anyone positioned on the origin side of the wire, could recover the proxy credentials: directly for Basic, or as a replayable and offline-crackable response for Digest.\n\n### Affected versions\n* 3.x: up to and including 3.0.11\n* 2.x: up to and including 2.16.0\n\n### Patches\nFixed in 3.0.12 on the 3.x line and in 2.16.1 on the 2.x line. The preemptive Proxy-Authorization header and the absolute-form request target are no longer attached to a tunnelled ws:// upgrade; a ws:// request is now treated like wss://.\n\n### Workarounds\nDo not use proxy authentication together with ws:// requests through an HTTP proxy, or use wss:// instead.\n\n### Details\nThe proxy-auth gate in NettyRequestFactory#newNettyRequest and the sibling branch in requestUri() did not exclude WebSocket URIs, even though the CONNECT-tunnelling check in NettyRequestSender already tunnels ws:// through CONNECT exactly like https://.\n\nNote that 3.0.12 is itself affected by a separate issue, GHSA-rqf5-2wxv-rjf4, where a Digest challenge the client cannot read downgrades to Basic and sends the password in cleartext. Upgrade to 3.0.13 to pick up both fixes.","aliases":["CVE-2026-107285"],"modified":"2026-10-08T16:45:18.877610661Z","published":"2026-10-08T16:30:58Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-08T16:30:58Z","nvd_published_at":"2026-10-07T22:17:04Z","cwe_ids":["CWE-319","CWE-522"]},"references":[{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-3wp9-xfwm-rjjf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107285"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/commit/6e9cb75a9b7259353f983fc90ca28b1da3742e18"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/commit/c4feab0f7f86d61505a48e40d383c8a375a22e18"},{"type":"PACKAGE","url":"https://github.com/AsyncHttpClient/async-http-client"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12"}],"affected":[{"package":{"name":"org.asynchttpclient:async-http-client","ecosystem":"Maven","purl":"pkg:maven/org.asynchttpclient/async-http-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.0.12"}]}],"versions":["3.0.0","3.0.1","3.0.10","3.0.11","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.0.11","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-3wp9-xfwm-rjjf/GHSA-3wp9-xfwm-rjjf.json"}},{"package":{"name":"org.asynchttpclient:async-http-client","ecosystem":"Maven","purl":"pkg:maven/org.asynchttpclient/async-http-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.16.1"}]}],"versions":["2.0.0","2.0.1","2.0.10","2.0.11","2.0.12","2.0.13","2.0.14","2.0.15","2.0.16","2.0.17","2.0.18","2.0.19","2.0.2","2.0.20","2.0.21","2.0.22","2.0.23","2.0.24","2.0.25","2.0.26","2.0.27","2.0.28","2.0.29","2.0.3","2.0.30","2.0.31","2.0.32","2.0.33","2.0.34","2.0.35","2.0.36","2.0.37","2.0.38","2.0.39","2.0.4","2.0.40","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.1.0","2.1.0-RC1","2.1.0-RC2","2.1.0-RC3","2.1.0-RC4","2.1.0-alpha1","2.1.0-alpha10","2.1.0-alpha11","2.1.0-alpha12","2.1.0-alpha13","2.1.0-alpha14","2.1.0-alpha15","2.1.0-alpha16","2.1.0-alpha17","2.1.0-alpha18","2.1.0-alpha19","2.1.0-alpha2","2.1.0-alpha20","2.1.0-alpha21","2.1.0-alpha22","2.1.0-alpha23","2.1.0-alpha24","2.1.0-alpha25","2.1.0-alpha26","2.1.0-alpha3","2.1.0-alpha4","2.1.0-alpha5","2.1.0-alpha6","2.1.0-alpha7","2.1.0-alpha8","2.1.0-alpha9","2.1.1","2.1.2","2.10.0","2.10.1","2.10.2","2.10.3","2.10.4","2.10.5","2.11.0","2.12.0","2.12.1","2.12.2","2.12.3","2.12.4","2.14.5","2.15.0","2.16.0","2.2.0","2.2.1","2.3.0","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.4.7","2.4.8","2.4.9","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.6.0","2.7.0","2.8.0","2.8.1","2.9.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.16.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-3wp9-xfwm-rjjf/GHSA-3wp9-xfwm-rjjf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}