Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, Realm.Builder generates the HTTP Digest client nonce with ThreadLocalRandom rather than a cryptographically secure random source. Digest relies on an unpredictable cnonce to resist chosen-plaintext and credential precomputation attacks, so an observer able to infer generator state can reduce the protection of the authentication exchange. This issue is fixed in versions 3.0.12 and 2.16.1.
Published: 2026-10-07
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Weak nonce generation in HTTP Digest authentication
Action: Patch
AI Analysis

Impact

AsyncHttpClient generates the HTTP Digest client nonce (cnonce) using ThreadLocalRandom, a non-cryptographic source, rather than a secure random generator. This reduces the unpredictability of the nonce, allowing an observer who can infer the generator state to anticipate the cnonce value. The vulnerability does not directly expose credentials, but it weakens the authentication chain, enabling chosen‑plaintext and credential precomputation attacks by reducing the effectiveness of Digest authentication.

Affected Systems

Any Java application that includes AsyncHttpClient before version 3.0.12 in the 3.x series or before 2.16.1 in the 2.x series and performs HTTP Digest authentication is affected. Applications relying on these older releases for client‑side authentication exchange are at risk.

Risk and Exploitability

The CVSS score of 3.7 indicates a low‑medium severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the likely attack vector involves an attacker with network visibility who can observe the authentication exchange; by capturing multiple exchanges the attacker could uncover patterns in the nonces and undermine the security guarantees of Digest authentication. Exploitation requires no special privileges beyond network monitoring, but the impact is limited to weakening authentication rather than directly releasing secrets.

Generated by OpenCVE AI on October 7, 2026 at 22:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the AsyncHttpClient dependency to version 3.0.12 or later (series 3) or 2.16.1 or later (series 2) to ensure a cryptographically secure random source is used for cnonce generation.
  • If an immediate upgrade is not possible, configure Realm.Builder to use SecureRandom or another cryptographically secure random source, overriding the default ThreadLocalRandom implementation.
  • Consider disabling HTTP Digest authentication in the affected applications and migrating to a stronger authentication scheme, such as OAuth2 or TLS‑protected Basic authentication.

Generated by OpenCVE AI on October 7, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-mfj3-87qq-382v AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random source
History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, Realm.Builder generates the HTTP Digest client nonce with ThreadLocalRandom rather than a cryptographically secure random source. Digest relies on an unpredictable cnonce to resist chosen-plaintext and credential precomputation attacks, so an observer able to infer generator state can reduce the protection of the authentication exchange. This issue is fixed in versions 3.0.12 and 2.16.1.
Title AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random source
Weaknesses CWE-338
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T14:00:20.347Z

Reserved: 2026-10-07T15:53:23.586Z

Link: CVE-2026-107283

cve-icon Vulnrichment

Updated: 2026-10-08T14:00:16.656Z

cve-icon NVD

Status : Received

Published: 2026-10-07T22:17:04.327

Modified: 2026-10-08T15:17:37.943

Link: CVE-2026-107283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:00:15Z

Weaknesses
  • CWE-338

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)