Authentication Vulnerability in AsyncHttpClient Library by AsyncHttpClient
CVE-2026-107283
3.7LOW
What is CVE-2026-107283?
The AsyncHttpClient library, crucial for executing HTTP requests in Java applications, contains a vulnerability in its nonce generation process. Prior to versions 3.0.12 and 2.16.1, the library used ThreadLocalRandom to generate HTTP Digest client nonces, which compromises the randomness needed for secure authentication. An attacker with knowledge of the nonce generation state could exploit this weakness to launch chosen-plaintext or credential precomputation attacks, diminishing the integrity of the authentication process. This vulnerability has been addressed in the aforementioned versions.
Affected Version(s)
async-http-client >= 3.0.0, < 3.0.12 < 3.0.0, 3.0.12
async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1
