2026-10-07 21:10CVE-2026-107279GitHub_M
PUBLISHED5.2CWE-303CWE-757

AsyncHttpClient: Digest mutual authentication is switched off by a peer offering qop=auth-int

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In 3.0.12, a peer offering only Digest qop=auth-int causes mutual-authentication verification to be skipped. AuthenticatorUtils.computeExpectedRspAuth returns no expected value for auth-int, and Interceptors treats that result as unverifiable but nonfatal, so a response with an invalid rspauth value is accepted. A peer that does not know the shared secret can therefore be accepted as the authenticated server. This issue is fixed in version 3.0.13.

Problem type

Affected products

AsyncHttpClient

async-http-client

= 3.0.12 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-107279
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-107279",
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "dateUpdated": "2026-10-07T21:10:51.519Z",
    "dateReserved": "2026-10-07T15:53:23.585Z",
    "datePublished": "2026-10-07T21:10:26.049Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M",
        "dateUpdated": "2026-10-07T21:10:51.519Z"
      },
      "title": "AsyncHttpClient: Digest mutual authentication is switched off by a peer offering qop=auth-int",
      "descriptions": [
        {
          "lang": "en",
          "value": "The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In 3.0.12, a peer offering only Digest qop=auth-int causes mutual-authentication verification to be skipped. AuthenticatorUtils.computeExpectedRspAuth returns no expected value for auth-int, and Interceptors treats that result as unverifiable but nonfatal, so a response with an invalid rspauth value is accepted. A peer that does not know the shared secret can therefore be accepted as the authenticated server. This issue is fixed in version 3.0.13."
        }
      ],
      "affected": [
        {
          "vendor": "AsyncHttpClient",
          "product": "async-http-client",
          "versions": [
            {
              "version": "= 3.0.12",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-303: Incorrect Implementation of Authentication Algorithm",
              "cweId": "CWE-303",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-757: Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')",
              "cweId": "CWE-757",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-qhv6-3pmh-95q4",
          "name": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-qhv6-3pmh-95q4",
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99",
          "name": "https://github.com/AsyncHttpClient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13",
          "name": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13",
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "metrics": [
        {}
      ]
    }
  }
}