PT-2026-94393 · Unknown · Async Http Client

·

CVE-2026-85717

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AsyncHttpClient versions 2.14.5 through 2.16.0 AsyncHttpClient versions 3.0.9 through 3.0.11
Description A client configured with a client-wide Realm and redirect following can disclose credentials during a cross-origin redirect. This occurs because the authentication path in the Interceptors falls back to the client configuration after the redirect handling clears the per-exchange realm. If an attacker-controlled target returns a 401 response, the client may send Basic or Digest credentials, or a Negotiate or NTLM token, to that origin. This issue is a residual bypass of previous cross-origin credential-stripping fixes.
Recommendations Update AsyncHttpClient versions 2.14.5 through 2.16.0 to version 2.16.1. Update AsyncHttpClient versions 3.0.9 through 3.0.11 to version 3.0.12. Set the Realm on the individual request instead of on the client configuration. Disable the follow-redirects feature.

Exploit

Fix

Insufficiently Protected Credentials

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85717
ECHO-7764-B5B5-9FBB
GHSA-F8M2-889X-VW4X

Affected Products

Async Http Client