Impact
The AsyncHttpClient library allows Java applications to perform HTTP requests and handle responses asynchronously. Versions 2.14.5 through 2.16.0 and 3.0.9 through 3.0.11 contain a flaw where a client configured with a client‑wide Realm and automatic redirect following may resend authentication credentials to a cross‑origin redirect target. During redirect handling, the per‑exchange realm is cleared, causing the Interceptor authentication logic to fall back to the client configuration. If the attacker‑controlled redirect target responds with 401, the client may send Basic, Digest, Negotiate, or NTLM tokens to that origin, disclosing sensitive credentials. This results in a confidentiality breach that allows an attacker to obtain authentication credentials that the application intended to keep private.
Affected Systems
The vulnerability impacts the AsyncHttpClient library from the AsyncHttpClient project. Affected release ranges are 2.14.5 through 2.16.0 and 3.0.9 through 3.0.11. Users of any Java application that incorporates these specific library versions and utilizes client‑wide realm authentication with redirect following are at risk.
Risk and Exploitability
The flaw carries a CVSS score of 6.8, indicating moderate severity. The EPSS score is <1%, reflecting a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to control a redirect destination that will return a 401 challenge; this can be achieved by hosting malicious content or manipulating server responses. While no public exploits are known, the potential for credential leakage makes the risk significant for sensitive environments.
OpenCVE Enrichment
Github GHSA