Authentication Vulnerability in AsyncHttpClient Library by AsyncHttpClient
CVE-2026-107283

3.7LOW

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-107283?

The AsyncHttpClient library, crucial for executing HTTP requests in Java applications, contains a vulnerability in its nonce generation process. Prior to versions 3.0.12 and 2.16.1, the library used ThreadLocalRandom to generate HTTP Digest client nonces, which compromises the randomness needed for secure authentication. An attacker with knowledge of the nonce generation state could exploit this weakness to launch chosen-plaintext or credential precomputation attacks, diminishing the integrity of the authentication process. This vulnerability has been addressed in the aforementioned versions.

Affected Version(s)

async-http-client >= 3.0.0, < 3.0.12 < 3.0.0, 3.0.12

async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.