PatchSiren cyber security CVE debrief
CVE-2026-107231 AsyncHttpClient CVE debrief
The AsyncHttpClient library, used by Java applications for HTTP requests, had a vulnerability prior to versions 3.0.13 and 2.16.1. A malicious origin or proxy could manipulate a Digest challenge to omit or empty the nonce, causing the client to resend credentials in cleartext using Basic authentication. This issue is fixed in the mentioned versions.
- Vendor
- AsyncHttpClient
- Product
- async-http-client
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders and developers using AsyncHttpClient in Java applications should be aware of this vulnerability and take steps to upgrade to fixed versions. Affected operators, platform administrators, vulnerability management teams, and security teams should prioritize verification of affected systems, review system inventory, and plan for updates to mitigate potential credential exposure.
Why it matters
Defenders should prioritize upgrading to fixed versions of AsyncHttpClient to prevent potential credential exposure due to improper handling of Digest challenges. This vulnerability allows a malicious origin or proxy to manipulate the challenge, causing the client to resend credentials in cleartext using Basic authentication. Affected systems and inventory checks require verification, and upgrading to versions 3.0.13 or 2.16.1 is essential.
- Potential credential exposure due to improper handling of Digest challenges
- Possible downgrade to Basic authentication, allowing reversible credential transmission
- Need for verification of affected systems and inventory checks
- Priority for upgrading to fixed versions of AsyncHttpClient
Technical summary
The AsyncHttpClient library, used by Java applications for HTTP requests, had a vulnerability prior to versions 3.0.13 and 2.16.1. A malicious origin or proxy could manipulate a Digest challenge to omit or empty the nonce, causing the client to resend credentials in cleartext using Basic authentication. This vulnerability affects Java applications utilizing AsyncHttpClient, particularly those with exposed systems or sensitive data. The issue is fixed in versions 3.0.13 and 2.16.1, and defenders should prioritize upgrading to these versions.
Defensive priority
Defenders should prioritize upgrading to fixed versions of AsyncHttpClient, specifically 3.0.13 or 2.16.1, to prevent potential credential exposure.
Recommended defensive actions
- Upgrade to AsyncHttpClient version 3.0.13 or 2.16.1
- Review and update affected Java applications using AsyncHttpClient
- Monitor for potential credential exposure
- Verify affected systems and inventory checks
- Prioritize upgrading to fixed versions of AsyncHttpClient
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, its impact, and fixed versions. However, there is limited information on potential exploitation or affected systems. Defenders should verify affected Java applications using AsyncHttpClient and review system inventory for potential exposure. Evidence from the CVE record and source item indicates a need for cautious verification of system configurations and updates to fixed versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107231 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107231
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107231 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107231
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
AsyncHttpClient: Digest challenge without a usable nonce downgrades to Basic and sends the passw
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107231.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rqf5-2wxv-rjf4
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/commit/8376866aa9b5a7653ad19db9d472692f875caa83
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/commit/c8d639bf6ac341d377d610a93570bcd15565f1a6
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.