Authentication Bypass Vulnerability in AsyncHttpClient Library
CVE-2026-85716

3.7LOW

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-85716?

The AsyncHttpClient library, widely used for executing HTTP requests in Java applications, contained a significant vulnerability that allowed for authentication bypass. Specifically, in versions 3.0.8 to 3.0.12, there was a flaw in the processing of SCRAM ServerSignature and Digest rspauth verification results. This vulnerability led to a situation where the library could authenticate a peer without proper validation of the shared secret, especially noticeable in non-TLS or compromised transport scenarios. An attacker could exploit this flaw to impersonate the server without having the correct credentials. While the issue has been addressed in version 3.0.12, it is crucial for users to update their installations to secure their applications from potential exploitation.

Affected Version(s)

async-http-client >= 3.0.8, < 3.0.12

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.