PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107231 AsyncHttpClient CVE debrief

The AsyncHttpClient library, used by Java applications for HTTP requests, had a vulnerability prior to versions 3.0.13 and 2.16.1. A malicious origin or proxy could manipulate a Digest challenge to omit or empty the nonce, causing the client to resend credentials in cleartext using Basic authentication. This issue is fixed in the mentioned versions.

Vendor
AsyncHttpClient
Product
async-http-client
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders and developers using AsyncHttpClient in Java applications should be aware of this vulnerability and take steps to upgrade to fixed versions. Affected operators, platform administrators, vulnerability management teams, and security teams should prioritize verification of affected systems, review system inventory, and plan for updates to mitigate potential credential exposure.

Why it matters

Defenders should prioritize upgrading to fixed versions of AsyncHttpClient to prevent potential credential exposure due to improper handling of Digest challenges. This vulnerability allows a malicious origin or proxy to manipulate the challenge, causing the client to resend credentials in cleartext using Basic authentication. Affected systems and inventory checks require verification, and upgrading to versions 3.0.13 or 2.16.1 is essential.

  • Potential credential exposure due to improper handling of Digest challenges
  • Possible downgrade to Basic authentication, allowing reversible credential transmission
  • Need for verification of affected systems and inventory checks
  • Priority for upgrading to fixed versions of AsyncHttpClient

Technical summary

The AsyncHttpClient library, used by Java applications for HTTP requests, had a vulnerability prior to versions 3.0.13 and 2.16.1. A malicious origin or proxy could manipulate a Digest challenge to omit or empty the nonce, causing the client to resend credentials in cleartext using Basic authentication. This vulnerability affects Java applications utilizing AsyncHttpClient, particularly those with exposed systems or sensitive data. The issue is fixed in versions 3.0.13 and 2.16.1, and defenders should prioritize upgrading to these versions.

Defensive priority

Defenders should prioritize upgrading to fixed versions of AsyncHttpClient, specifically 3.0.13 or 2.16.1, to prevent potential credential exposure.

Recommended defensive actions

  • Upgrade to AsyncHttpClient version 3.0.13 or 2.16.1
  • Review and update affected Java applications using AsyncHttpClient
  • Monitor for potential credential exposure
  • Verify affected systems and inventory checks
  • Prioritize upgrading to fixed versions of AsyncHttpClient
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability, its impact, and fixed versions. However, there is limited information on potential exploitation or affected systems. Defenders should verify affected Java applications using AsyncHttpClient and review system inventory for potential exposure. Evidence from the CVE record and source item indicates a need for cautious verification of system configurations and updates to fixed versions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107231 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107231

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107231 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107231

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • AsyncHttpClient: Digest challenge without a usable nonce downgrades to Basic and sends the passw

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107231.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rqf5-2wxv-rjf4

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/8376866aa9b5a7653ad19db9d472692f875caa83

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/c8d639bf6ac341d377d610a93570bcd15565f1a6

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.