Cross-Origin Credential Disclosure in AsyncHttpClient Library
CVE-2026-85717

6.8MEDIUM

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-85717?

The AsyncHttpClient library, widely used for executing HTTP requests in Java applications, is susceptible to a vulnerability that may allow an attacker to gain unauthorized access to user credentials following a cross-origin redirect. Specifically, when clients are configured with a client-wide Realm, their authentication credentials can be inadvertently sent to an attacker-controlled site. This occurs because the authentication infrastructure fails to adequately strip per-request realms after a redirect, leading to potential exposure of Basic, Digest, or NTLM credentials upon receiving a 401 Unauthorized response from the target. This vulnerability has been addressed in AsyncHttpClient versions 2.16.1 and 3.0.12.

Affected Version(s)

async-http-client >= 2.14.5, < 2.16.1 < 2.14.5, 2.16.1

async-http-client >= 3.0.9, < 3.0.12 < 3.0.9, 3.0.12

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.