Cleartext transmission of sensitive information in Async-http-client - #VU142451
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to cleartext transmission of sensitive information in the HTTP CONNECT tunnel setup in Async-http-client when sending requests through an HTTP proxy to an HTTPS origin with preemptive origin authentication. A remote attacker can observe a plaintext CONNECT request carrying origin credentials or authentication tokens to disclose sensitive information.
The issue affects Basic credentials as well as NTLM, SPNEGO, and Kerberos tokens on the client-to-proxy hop before TLS is established.