{"id":"CVE-2026-85717","summary":"AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect target","details":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redirect following can disclose credentials after a cross-origin redirect because the Interceptors authentication path falls back to the client configuration after redirect handling clears the per-exchange realm. If the attacker-controlled target returns 401, the client can send Basic or Digest credentials or a Negotiate or NTLM token to that origin. Per-request realms are stripped correctly, and this issue is a residual bypass of the earlier cross-origin credential-stripping fixes. This issue is fixed in versions 2.16.1 and 3.0.12.","aliases":["GHSA-f8m2-889x-vw4x"],"modified":"2026-09-18T08:05:15.698058Z","published":"2026-09-17T15:53:39.875Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-200","CWE-522"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85717.json"},"references":[{"type":"FIX","url":"https://github.com/AsyncHttpClient/async-http-client/commit/43db7bba81430cbd61ec2dc2c7be464e0ff6a0ff"},{"type":"FIX","url":"https://github.com/AsyncHttpClient/async-http-client/commit/b66757bec34def2e9867bb2b77bd848b1112abb4"},{"type":"FIX","url":"https://github.com/AsyncHttpClient/async-http-client/pull/2224"},{"type":"ADVISORY","url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f8m2-889x-vw4x"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85717.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85717"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asynchttpclient/async-http-client","events":[{"introduced":"ae557ad35246721c09dafb2976609cd0004e78ae"},{"fixed":"d1f0ccec417092098d40242fee7dfac84bb3c21f"},{"introduced":"1ab1ea31fcaa0b016130d9f08cd5334feb2d1d93"},{"fixed":"c07038b44e5206375662b46859672e8f1df9f05a"}],"database_specific":{"extracted_events":[{"introduced":"2.14.5"},{"fixed":"2.16.1"},{"introduced":"3.0.9"},{"fixed":"3.0.12"}],"source":"AFFECTED_FIELD"}}],"versions":["async-http-client-project-2.16.0","async-http-client-project-2.15.0","async-http-client-project-3.0.11","async-http-client-project-3.0.10","async-http-client-project-3.0.9","async-http-client-project-2.14.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85717.json","vanir_signatures_modified":"2026-09-18T08:05:15Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f","target":{"file":"client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java"},"deprecated":false,"digest":{"line_hashes":["219246596221720898981563676126452787927","112413554918931264338179563940130289539","262908889413526511266896616639455764237"],"threshold":0.9},"id":"CVE-2026-85717-26220b3f","signature_type":"Line"},{"signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f","target":{"file":"client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java","function":"add"},"deprecated":false,"digest":{"function_hash":"319981061666573934872902157208912328509","length":685},"id":"CVE-2026-85717-c7b286ac","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}