GHSA-3wp9-xfwm-rjjf

Suggest an improvement
Source
https://github.com/advisories/GHSA-3wp9-xfwm-rjjf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-3wp9-xfwm-rjjf/GHSA-3wp9-xfwm-rjjf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3wp9-xfwm-rjjf
Aliases
Published
2026-10-08T16:30:58Z
Modified
2026-10-08T16:45:18Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunnel
Details

Impact

When a ws:// request is routed through an HTTP proxy with proxy authentication configured, the client tunnels the connection with an HTTP CONNECT, the same as it does for https://. Once the tunnel is open, the WebSocket upgrade request that follows is sent through the tunnel directly to the origin server, not to the proxy. The proxy-auth gate and the companion request-target selection keyed only on whether the URI was secured, which is false for ws://, so the tunnelled upgrade request incorrectly carried the proxy's Proxy-Authorization header and an absolute-form request target meant for the proxy. Any origin server reached over a proxied ws:// connection, or anyone positioned on the origin side of the wire, could recover the proxy credentials: directly for Basic, or as a replayable and offline-crackable response for Digest.

Affected versions

  • 3.x: up to and including 3.0.11
  • 2.x: up to and including 2.16.0

Patches

Fixed in 3.0.12 on the 3.x line and in 2.16.1 on the 2.x line. The preemptive Proxy-Authorization header and the absolute-form request target are no longer attached to a tunnelled ws:// upgrade; a ws:// request is now treated like wss://.

Workarounds

Do not use proxy authentication together with ws:// requests through an HTTP proxy, or use wss:// instead.

Details

The proxy-auth gate in NettyRequestFactory#newNettyRequest and the sibling branch in requestUri() did not exclude WebSocket URIs, even though the CONNECT-tunnelling check in NettyRequestSender already tunnels ws:// through CONNECT exactly like https://.

Note that 3.0.12 is itself affected by a separate issue, GHSA-rqf5-2wxv-rjf4, where a Digest challenge the client cannot read downgrades to Basic and sends the password in cleartext. Upgrade to 3.0.13 to pick up both fixes.

Database specific
{
    "cwe_ids": [
        "CWE-319",
        "CWE-522"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-08T16:30:58Z",
    "nvd_published_at": "2026-10-07T22:17:04Z",
    "severity": "MODERATE"
}
References

Affected packages

Maven / org.asynchttpclient:async-http-client

Package

Name
org.asynchttpclient:async-http-client
View open source insights on deps.dev
Purl
pkg:maven/org.asynchttpclient/async-http-client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
3.0.12

Affected versions

3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.0.10
3.0.11

Database specific

last_known_affected_version_range
"<= 3.0.11"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-3wp9-xfwm-rjjf/GHSA-3wp9-xfwm-rjjf.json"

Maven / org.asynchttpclient:async-http-client

Package

Name
org.asynchttpclient:async-http-client
View open source insights on deps.dev
Purl
pkg:maven/org.asynchttpclient/async-http-client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.16.1

Affected versions

2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.1.0-alpha1
2.1.0-alpha2
2.1.0-alpha3
2.1.0-alpha4
2.1.0-alpha5
2.1.0-alpha6
2.1.0-alpha7
2.1.0-alpha8
2.1.0-alpha9
2.1.0-alpha10
2.1.0-alpha11
2.1.0-alpha12
2.1.0-alpha13
2.1.0-alpha14
2.1.0-alpha15
2.1.0-alpha16
2.1.0-alpha17
2.1.0-alpha18
2.1.0-alpha19
2.1.0-alpha20
2.1.0-alpha21
2.1.0-alpha22
2.1.0-alpha23
2.1.0-alpha24
2.1.0-alpha25
2.1.0-alpha26
2.1.0-RC1
2.1.0-RC2
2.1.0-RC3
2.1.0-RC4
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.6.0
2.7.0
2.8.0
2.8.1
2.9.0
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.14.5
2.15.0
2.16.0

Database specific

last_known_affected_version_range
"<= 2.16.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-3wp9-xfwm-rjjf/GHSA-3wp9-xfwm-rjjf.json"