When a request is replayed onto a different host, the client updates only the current request and leaves the target request pointing at the original host. Four consumers read that stale value, and each one sends the first host's request, credentials, or both to the second host.
A replay happens through documented, ordinary features: a ResponseFilter that returns a different request, which is the supported failover pattern, and the IOException retry path. The attacker does not need to induce the replay; an application that uses failover produces it by design.
Authorization header goes to B.Host, and A's Authorization. TLS does not protect against this, because the handshake really is with B, so no certificate mismatch occurs.http:// and the replay is https://, no SSL handler is installed and the replayed request, credentials included, is written in cleartext.Both lines are affected identically. This is long-standing behaviour, not a recent regression.
Fixed in 3.0.13 on the 3.x line and in 2.16.1 on the 2.x line. The target request now moves when a request is replayed, and the proxy moves with it: the proxy is part of the connection pool key, so correcting only the host would convert a harmless pool miss into a hit and route a proxied connection to a direct request.
Do not use a ResponseFilter that replays to a different host, and disable request retries, if the client is configured with credentials or used through a proxy. Replaying to the same host is not affected.
NettyRequestSender.newNettyRequestAndResponseFuture calls setCurrentRequest without setTargetRequest, and replayRequest does not move the target either. The stale target is then read by the pool key derivation in NettyResponseFuture, by ConnectSuccessInterceptor when it writes the tunnelled request, by the realm selection in NettyRequestSender, and by NettyConnectListener when it decides whether to install an SSL handler.
Existing replay tests do not cover this, because all of them replay to the same host.
{
"cwe_ids": [
"CWE-319",
"CWE-441",
"CWE-522"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-08T16:30:46Z",
"nvd_published_at": "2026-10-07T22:17:04Z",
"severity": "CRITICAL"
}