THREAT OPS › Threat News › [GHSA] GHSA-xr57-gcx8-52hf (medium) — AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request
[GHSA] GHSA-xr57-gcx8-52hf (medium) — AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request
GHSA-xr57-gcx8-52hf Severity: medium CVE: CVE-2026-85720
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request
### Impact When a request uses an HTTP proxy to reach an HTTPS origin, the client opens the tunnel with a plaintext CONNECT sent to the proxy before any TLS exists. On affected versions the origin's preemptive credentials were added to that CONNECT. A Ba
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-85720cve
Original source: https://github.com/advisories/GHSA-xr57-gcx8-52hf