Echo: async-http-client, org.asynchttpclient:async-http-client: security update to 2.16.1

medium Tenable Cloud Security Plugin ID 457248

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and
asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured
with a client-wide Realm and redirect following can disclose credentials after a cross-origin redirect
because the Interceptors authentication path falls back to the client configuration after redirect
handling clears the per-exchange realm. If the attacker-controlled target returns 401, the client can send
Basic or Digest credentials or a Negotiate or NTLM token to that origin. Per-request realms are stripped
correctly, and this issue is a residual bypass of the earlier cross-origin credential-stripping fixes.
This issue is fixed in versions 2.16.1 and 3.0.12. (CVE-2026-85717)

Solution

Update the async-http-client library and its related packages to version 2.16.1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-85717

Plugin Details

Severity: Medium

ID: 457248

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.3

Percentile: 50.56

CVSS v2

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2026-85717

CVSS v3

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 9/17/2026

Reference Information

CVE: CVE-2026-85717