Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In 3.0.12, a peer offering only Digest qop=auth-int causes mutual-authentication verification to be skipped. AuthenticatorUtils.computeExpectedRspAuth returns no expected value for auth-int, and Interceptors treats that result as unverifiable but nonfatal, so a response with an invalid rspauth value is accepted. A peer that does not know the shared secret can therefore be accepted as the authenticated server. This issue is fixed in version 3.0.13.
Published: 2026-10-07
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Authentication bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability occurs in AsyncHttpClient 3.0.12 when a peer presents a Digest authentication challenge with qop=auth-int. The client computes no expected rspauth value for auth-int, and the framework treats the missing value as unverifiable yet acceptable. As a result, a malicious server that does not know the shared secret can gain authenticated status, effectively spoofing the server for the client. This flaw permits an attacker to pass the mutual‑authentication check and potentially gain unilateral trust of the client, enabling further compromise such as data tampering or denial of service. The weakness aligns with authentication flaws identified in CWEs 303 and 757.

Affected Systems

Any Java application that incorporates AsyncHttpClient version 3.0.12 and uses Digest authentication with qop=auth-int is affected. The issue is resolved in the 3.0.13 release; earlier iterations such as 3.0.12 remain vulnerable.

Risk and Exploitability

The CVSS score of 8.8 reflects a high severity authentication bypass. EPSS data is not available, but the vulnerability is not listed in the CISA KEV catalog, suggesting no public exploit campaigns have been documented to date. Likely exploitation would occur over a network channel where the client initiates a digest challenge to a server; an attacker could provide a forged response to satisfy the client’s validation logic. The attack vector is therefore remote network, with minimal prerequisites beyond an ability to present a response to the client’s digest challenge.

Generated by OpenCVE AI on October 7, 2026 at 22:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to AsyncHttpClient 3.0.13 or later to apply the fix that rejects auth‑int qop values lacking a valid rspauth.
  • Configure the client to avoid using Digest authentication with qop=auth-int, or disable Digest authentication entirely if not required.
  • Apply network monitoring or firewall rules to detect unexpected Digest challenges with auth‑int, and block or alert on such traffic.

Generated by OpenCVE AI on October 7, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In 3.0.12, a peer offering only Digest qop=auth-int causes mutual-authentication verification to be skipped. AuthenticatorUtils.computeExpectedRspAuth returns no expected value for auth-int, and Interceptors treats that result as unverifiable but nonfatal, so a response with an invalid rspauth value is accepted. A peer that does not know the shared secret can therefore be accepted as the authenticated server. This issue is fixed in version 3.0.13.
Title AsyncHttpClient: Digest mutual authentication is switched off by a peer offering qop=auth-int
Weaknesses CWE-303
CWE-757
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T21:10:51.519Z

Reserved: 2026-10-07T15:53:23.585Z

Link: CVE-2026-107279

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T22:17:03.657

Modified: 2026-10-07T22:17:03.657

Link: CVE-2026-107279

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T22:45:17Z

Weaknesses
  • CWE-303

    Incorrect Implementation of Authentication Algorithm

  • CWE-757

    Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')