THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f8m2-889x-vw4x (medium) — AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target

[GHSA] GHSA-f8m2-889x-vw4x (medium) — AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target

medgithub_advisoriesPublished 2026-09-17

GHSA-f8m2-889x-vw4x Severity: medium CVE: CVE-2026-85717

AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target

### Impact A client configured with a client-wide realm (a Realm set on the config builder rather than on an individual request) and following redirects could re-send those credentials to a redirect target on a different origin. The redirect code strip

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f8m2-889x-vw4x