Insufficiently protected credentials in Async-http-client - #VU142434

 

Insufficiently protected credentials in Async-http-client - #VU142434

Published: August 13, 2026


Vulnerability identifier: #VU142434
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-522
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to insufficiently protected credentials in replay handling in async-http-client when replaying a request to a different host. A remote attacker can receive a replayed request or credentials on a different host to disclose sensitive information.

The issue can also cause requests and credentials to be sent in cleartext when the original request used HTTP and the replayed request used HTTPS.


Affected software

Async-http-client

Remediation

Install security update from vendor's website.

Async-http-client - addressed in versions 2.16.1, 3.0.13

External References

Related Security Bulletins