Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, Realm.Builder treats a Digest challenge that yields no usable nonce as a Basic challenge. A malicious origin or proxy can label a challenge Digest while omitting or emptying the nonce, causing the client to resend the username and password using reversible Basic authentication. Both origin and proxy challenge parsers are affected. This issue is fixed in versions 3.0.13 and 2.16.1.
Published: 2026-10-07
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Credential Theft
Action: Patch
AI Analysis

Impact

The AsyncHttpClient library misinterprets a Digest authentication challenge that lacks a usable nonce as a Basic challenge, causing the client to send the username and password in plain text. This flaw allows an attacker to capture credentials that were intended to remain confidential, representing a cleartext transmission vulnerability. The issue is rooted in improper handling of authentication semantics and is classified under CWE‑319, CWE‑522, and CWE‑757.

Affected Systems

Java applications that incorporate the AsyncHttpClient library before version 3.0.13 or 2.16.1 are affected. The vulnerability applies to both the standard and proxy-enabled implementations of the client, meaning any upstream or intermediary proxy that can alter the Digest challenge will trigger the flaw.

Risk and Exploitability

With a CVSS score of 8.7, this vulnerability is considered high severity. The EPSS score is not provided, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that it may not have widespread public exploitation yet. A malicious origin or proxy that can inject a Digest challenge without a nonce can coerce the client into sending Basic authentication credentials. Exploitation requires the attacker to influence the client’s authentication flow, which is feasible through network manipulation or compromised network elements. The impact could be significant if the attacker gains access to user credentials used by the application.

Generated by OpenCVE AI on October 7, 2026 at 22:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the AsyncHttpClient library to version 3.0.13 or 2.16.1 or later to apply the fixed logic preventing the Basic fallback.
  • Verify that all network proxies and intermediaries are trusted and enforce strict authentication challenge compliance; avoid using untrusted or misconfigured proxies that could modify authentication headers.
  • As a temporary workaround if an immediate upgrade is not possible, configure the application to disable the fall back to Basic authentication for Digest challenges lacking a nonce, or ensure that all authentication occurs over a secure TLS channel and avoid unencrypted Basic authentication.

Generated by OpenCVE AI on October 7, 2026 at 22:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, Realm.Builder treats a Digest challenge that yields no usable nonce as a Basic challenge. A malicious origin or proxy can label a challenge Digest while omitting or emptying the nonce, causing the client to resend the username and password using reversible Basic authentication. Both origin and proxy challenge parsers are affected. This issue is fixed in versions 3.0.13 and 2.16.1.
Title AsyncHttpClient: Digest challenge without a usable nonce downgrades to Basic and sends the password in cleartext
Weaknesses CWE-319
CWE-522
CWE-757
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T21:06:26.742Z

Reserved: 2026-10-07T14:34:14.817Z

Link: CVE-2026-107231

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T22:17:03.320

Modified: 2026-10-07T22:17:03.320

Link: CVE-2026-107231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T22:45:17Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information

  • CWE-522

    Insufficiently Protected Credentials

  • CWE-757

    Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')