Back to database
Schedule48High8.7VulnerabilityCVE-2026-107231No patch link observed

CVE-2026-107231 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.

Published Oct 7, 2026, 10:17 PM UTCIngested 1d agoSource NVD(cve-db)CVE-2026-107231

Description

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, Realm.Builder treats a Digest challenge that yields no usable nonce as a Basic challenge. A malicious origin or proxy can label a challenge Digest while omitting or emptying the nonce, causing the client to resend the username and password using reversible Basic authentication. Both origin and proxy challenge parsers are affected. This issue is fixed in versions 3.0.13 and 2.16.1.

CVSS v4.0 base metrics

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.7

High severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

AT

None

Attack Requirements

PR

None

Privileges Required

UI

None

User Interaction

VC

High

Confidentiality (Vulnerable System)

VI

None

Integrity (Vulnerable System)

VA

None

Availability (Vulnerable System)

SC

None

Confidentiality (Subsequent System)

SI

None

Integrity (Subsequent System)

SA

None

Availability (Subsequent System)

Affected

Vendor
Maven
Product
org.asynchttpclient:async-http-client

Versions

  • pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0.Beta1, < 3.0.13
  • pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1

Stated as the source expressed them.