Insufficiently protected credentials in Async-http-client - #VU142434
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to insufficiently protected credentials in replay handling in async-http-client when replaying a request to a different host. A remote attacker can receive a replayed request or credentials on a different host to disclose sensitive information.
The issue can also cause requests and credentials to be sent in cleartext when the original request used HTTP and the replayed request used HTTPS.