CVE-2026-107231 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.
Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, Realm.Builder treats a Digest challenge that yields no usable nonce as a Basic challenge. A malicious origin or proxy can label a challenge Digest while omitting or emptying the nonce, causing the client to resend the username and password using reversible Basic authentication. Both origin and proxy challenge parsers are affected. This issue is fixed in versions 3.0.13 and 2.16.1.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
None
Privileges Required
UI
None
User Interaction
VC
High
Confidentiality (Vulnerable System)
VI
None
Integrity (Vulnerable System)
VA
None
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
Affected
- Vendor
- Maven
- Product
- org.asynchttpclient:async-http-client
Versions
- pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0.Beta1, < 3.0.13
- pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1
Stated as the source expressed them.
References
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/commit/8376866aa9b5a7653ad19db9d472692f875caa83
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/commit/c8d639bf6ac341d377d610a93570bcd15565f1a6
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13
- advisory[email protected]https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rqf5-2wxv-rjf4
- advisoryOSV GHSA-rqf5-2wxv-rjf4https://osv.dev/vulnerability/GHSA-rqf5-2wxv-rjf4
- advisoryOSV advisoryhttps://nvd.nist.gov/vuln/detail/CVE-2026-107231
- vendorOSV packagehttps://github.com/AsyncHttpClient/async-http-client
Related threats
same CWE or vendorCVE-2026-107715 — The Mechanize library is used for automating interaction with websites.
CVE-2026-107715 · 4h ago
CVE-2026-107714 — The Mechanize library is used for automating interaction with websites.
CVE-2026-107714 · 4h ago
CVE-2026-107399 — The Mechanize library is used for automating interaction with websites.
CVE-2026-107399 · 4h ago
AsyncHttpClient: Cookies received over plaintext HTTP can plant, overwrite or delete Secure cookies set over HTTPS
CVE-2026-107226 · 9h ago
CVE-2026-105833 — EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account sc…
CVE-2026-105833 · 11h ago
CVE-2026-104704 — Progressive Robot hMailServer 6.0.0 through 6.3.5 does not enforce TLS for outbound SMTP delivery to a mail exchanger whose DNSSEC-validated TLSA r…
CVE-2026-104704 · 15h ago