Impact
AsyncHttpClient generates the HTTP Digest client nonce (cnonce) using ThreadLocalRandom, a non-cryptographic source, rather than a secure random generator. This reduces the unpredictability of the nonce, allowing an observer who can infer the generator state to anticipate the cnonce value. The vulnerability does not directly expose credentials, but it weakens the authentication chain, enabling chosen‑plaintext and credential precomputation attacks by reducing the effectiveness of Digest authentication.
Affected Systems
Any Java application that includes AsyncHttpClient before version 3.0.12 in the 3.x series or before 2.16.1 in the 2.x series and performs HTTP Digest authentication is affected. Applications relying on these older releases for client‑side authentication exchange are at risk.
Risk and Exploitability
The CVSS score of 3.7 indicates a low‑medium severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the likely attack vector involves an attacker with network visibility who can observe the authentication exchange; by capturing multiple exchanges the attacker could uncover patterns in the nonces and undermine the security guarantees of Digest authentication. Exploitation requires no special privileges beyond network monitoring, but the impact is limited to weakening authentication rather than directly releasing secrets.
OpenCVE Enrichment
Github GHSA