Vulnerability GHSA-3wp9-xfwm-rjjf

Medium Risk
MEDIUM RISK
CVSS Score: 5.9
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
6 hours ago
October 08, 2026 at 04:30 PM UTC
AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunnel
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.0
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.0

Summary

AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunnel

Details

Impact

When a ws:// request is routed through an HTTP proxy with proxy authentication configured, the client tunnels the connection with an HTTP CONNECT, the same as it does for https://. Once the tunnel is open, the WebSocket upgrade request that follows is sent through the tunnel directly to the origin server, not to the proxy. The proxy-auth gate and the companion request-target selection keyed only on whether the URI was secured, which is false for ws://, so the tunnelled upgrade request incorrectly carried the proxy's Proxy-Authorization header and an absolute-form request target meant for the proxy. Any origin server reached over a proxied ws:// connection, or anyone positioned on the origin side of the wire, could recover the proxy credentials: directly for Basic, or as a replayable and offline-crackable response for Digest.

Affected versions

  • 3.x: up to and including 3.0.11
  • 2.x: up to and including 2.16.0

Patches

Fixed in 3.0.12 on the 3.x line and in 2.16.1 on the 2.x line. The preemptive Proxy-Authorization header and the absolute-form request target are no longer attached to a tunnelled ws:// upgrade; a ws:// request is now treated like wss://.

Workarounds

Do not use proxy authentication together with ws:// requests through an HTTP proxy, or use wss:// instead.

Details

The proxy-auth gate in NettyRequestFactory#newNettyRequest and the sibling branch in requestUri() did not exclude WebSocket URIs, even though the CONNECT-tunnelling check in NettyRequestSender already tunnels ws:// through CONNECT exactly like https://.

Note that 3.0.12 is itself affected by a separate issue, GHSA-rqf5-2wxv-rjf4, where a Digest challenge the client cannot read downgrades to Basic and sends the password in cleartext. Upgrade to 3.0.13 to pick up both fixes.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Medium Risk
6 hours ago
AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHeader (Bypass of CVE-2024-53990 Fix)
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-2jwh-9rmr-j4xf
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-2jwh-9rmr-j4xf
Medium Risk
6 hours ago
AsyncHttpClient: Cookies received over plaintext HTTP can plant, overwrite or delete Secure cookies set over HTTPS
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-p2jm-6hj6-9rjg
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-p2jm-6hj6-9rjg
High Risk
6 hours ago
AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompression-bomb denial of service when compression is enabled
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-x8v2-478q-2hvg
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-x8v2-478q-2hvg
High Risk
6 hours ago
AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-v2j5-22fr-j62r
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-v2j5-22fr-j62r
Low Risk
6 hours ago
AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random source
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.0 GHSA-mfj3-87qq-382v
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.0 GHSA-mfj3-87qq-382v
View all vulnerabilities for these packages

Timeline

Published
6 hours ago
October 08, 2026 at 04:30 PM UTC
Fixed (3.0.12)
Unknown
Unknown
Fixed (2.16.1)
Unknown
Unknown
Last Modified
6 hours ago
October 08, 2026 at 04:45 PM UTC