Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redirect following can disclose credentials after a cross-origin redirect because the Interceptors authentication path falls back to the client configuration after redirect handling clears the per-exchange realm. If the attacker-controlled target returns 401, the client can send Basic or Digest credentials or a Negotiate or NTLM token to that origin. Per-request realms are stripped correctly, and this issue is a residual bypass of the earlier cross-origin credential-stripping fixes. This issue is fixed in versions 2.16.1 and 3.0.12.
Published: 2026-09-17
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential Disclosure via Cross-Origin Redirect,
Action: Apply Patch
AI Analysis

Impact

The AsyncHttpClient library allows Java applications to perform HTTP requests and handle responses asynchronously. Versions 2.14.5 through 2.16.0 and 3.0.9 through 3.0.11 contain a flaw where a client configured with a client‑wide Realm and automatic redirect following may resend authentication credentials to a cross‑origin redirect target. During redirect handling, the per‑exchange realm is cleared, causing the Interceptor authentication logic to fall back to the client configuration. If the attacker‑controlled redirect target responds with 401, the client may send Basic, Digest, Negotiate, or NTLM tokens to that origin, disclosing sensitive credentials. This results in a confidentiality breach that allows an attacker to obtain authentication credentials that the application intended to keep private.

Affected Systems

The vulnerability impacts the AsyncHttpClient library from the AsyncHttpClient project. Affected release ranges are 2.14.5 through 2.16.0 and 3.0.9 through 3.0.11. Users of any Java application that incorporates these specific library versions and utilizes client‑wide realm authentication with redirect following are at risk.

Risk and Exploitability

The flaw carries a CVSS score of 6.8, indicating moderate severity. The EPSS score is <1%, reflecting a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to control a redirect destination that will return a 401 challenge; this can be achieved by hosting malicious content or manipulating server responses. While no public exploits are known, the potential for credential leakage makes the risk significant for sensitive environments.

Generated by OpenCVE AI on September 20, 2026 at 04:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AsyncHttpClient to version 2.16.1 or later, or 3.0.12 or later.
  • Disable automatic redirect following or configure per‑request realm authentication to avoid using client‑wide realms on redirects.
  • If upgrading is not immediately possible, remove or alter the client‑wide realm setting and instead supply authentication credentials on a per‑request basis or use a custom interceptor to strip credentials before following a cross‑origin redirect.

Generated by OpenCVE AI on September 20, 2026 at 04:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f8m2-889x-vw4x AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target
History

Fri, 25 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Asynchttpclient Project
Asynchttpclient Project async-http-client
Vendors & Products Asynchttpclient Project
Asynchttpclient Project async-http-client

Thu, 17 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redirect following can disclose credentials after a cross-origin redirect because the Interceptors authentication path falls back to the client configuration after redirect handling clears the per-exchange realm. If the attacker-controlled target returns 401, the client can send Basic or Digest credentials or a Negotiate or NTLM token to that origin. Per-request realms are stripped correctly, and this issue is a residual bypass of the earlier cross-origin credential-stripping fixes. This issue is fixed in versions 2.16.1 and 3.0.12.
Title AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect target
Weaknesses CWE-200
CWE-522
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Asynchttpclient Project Async-http-client
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-23T18:46:54.135Z

Reserved: 2026-09-04T14:45:10.648Z

Link: CVE-2026-85717

cve-icon Vulnrichment

Updated: 2026-09-23T18:42:37.228Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:18:15.960

Modified: 2026-09-30T17:31:44.573

Link: CVE-2026-85717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-522

    Insufficiently Protected Credentials