PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107279 AsyncHttpClient CVE debrief

The AsyncHttpClient library, used for executing HTTP requests and processing responses in Java applications, had a vulnerability in version 3.0.12. When a peer offered only Digest qop=auth-int, mutual-authentication verification was skipped due to how AuthenticatorUtils.computeExpectedRspAuth and Interceptors handled the response. This allowed a peer that did not know the shared secret to be accepted as the authenticated server. The issue was fixed in version 3.0.13.

Vendor
AsyncHttpClient
Product
async-http-client
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders and developers using AsyncHttpClient version 3.0.12, especially those relying on Digest authentication for secure communication, should assess exposure and prioritize upgrading to version 3.0.13.

Why it matters

CVE-2026-107279 allows potentially unauthenticated server access in AsyncHttpClient 3.0.12 when a peer offers Digest qop=auth-int. Defenders should verify and upgrade to version 3.0.13, review affected systems, and monitor for unusual authentication attempts.

  • Potential unauthorized server access due to skipped mutual authentication
  • Possible authentication bypass in systems relying on Digest authentication
  • Need for verification of server authenticity in affected deployments
  • Priority on upgrading to AsyncHttpClient version 3.0.13

Technical summary

In AsyncHttpClient 3.0.12, a peer offering only Digest qop=auth-int causes mutual-authentication verification to be skipped. This is due to AuthenticatorUtils.computeExpectedRspAuth returning no expected value for auth-int, and Interceptors treating that result as unverifiable but nonfatal. As a result, a response with an invalid rspauth value is accepted, allowing a peer that does not know the shared secret to be accepted as the authenticated server.

Defensive priority

Defenders should prioritize verifying and upgrading to AsyncHttpClient version 3.0.13 if using 3.0.12, especially in systems relying on Digest authentication for secure communication.

Recommended defensive actions

  • Verify and upgrade to AsyncHttpClient version 3.0.13 if using 3.0.12
  • Review systems relying on Digest authentication for secure communication
  • Monitor for unusual authentication attempts or server responses
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details on the vulnerability, its impact, and the fix in version 3.0.13. However, specific details about affected deployments or active exploitation are not provided.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107279 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107279

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107279 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107279

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • AsyncHttpClient: Digest mutual authentication is switched off by a peer offering qop=auth-int

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107279.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-qhv6-3pmh-95q4

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.