Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f8m2-889x-vw4x | AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target |
Thu, 17 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redirect following can disclose credentials after a cross-origin redirect because the Interceptors authentication path falls back to the client configuration after redirect handling clears the per-exchange realm. If the attacker-controlled target returns 401, the client can send Basic or Digest credentials or a Negotiate or NTLM token to that origin. Per-request realms are stripped correctly, and this issue is a residual bypass of the earlier cross-origin credential-stripping fixes. This issue is fixed in versions 2.16.1 and 3.0.12. | |
| Title | AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect target | |
| Weaknesses | CWE-200 CWE-522 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-17T15:53:39.875Z
Reserved: 2026-09-04T14:45:10.648Z
Link: CVE-2026-85717
No data.
Status : Received
Published: 2026-09-17T16:18:15.960
Modified: 2026-09-17T16:18:15.960
Link: CVE-2026-85717
No data.
OpenCVE Enrichment
No data.

Github GHSA