Cross-Origin Credential Disclosure in AsyncHttpClient Library
CVE-2026-85717
What is CVE-2026-85717?
The AsyncHttpClient library, widely used for executing HTTP requests in Java applications, is susceptible to a vulnerability that may allow an attacker to gain unauthorized access to user credentials following a cross-origin redirect. Specifically, when clients are configured with a client-wide Realm, their authentication credentials can be inadvertently sent to an attacker-controlled site. This occurs because the authentication infrastructure fails to adequately strip per-request realms after a redirect, leading to potential exposure of Basic, Digest, or NTLM credentials upon receiving a 401 Unauthorized response from the target. This vulnerability has been addressed in AsyncHttpClient versions 2.16.1 and 3.0.12.
Affected Version(s)
async-http-client >= 2.14.5, < 2.16.1 < 2.14.5, 2.16.1
async-http-client >= 3.0.9, < 3.0.12 < 3.0.9, 3.0.12
