AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect target (CVE-2026-85717) | HOL Guard CVE