THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xr57-gcx8-52hf (medium) — AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request

[GHSA] GHSA-xr57-gcx8-52hf (medium) — AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request

medgithub_advisoriesPublished 2026-09-17

GHSA-xr57-gcx8-52hf Severity: medium CVE: CVE-2026-85720

AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request

### Impact When a request uses an HTTP proxy to reach an HTTPS origin, the client opens the tunnel with a plaintext CONNECT sent to the proxy before any TLS exists. On affected versions the origin's preemptive credentials were added to that CONNECT. A Ba

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xr57-gcx8-52hf