PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107283 AsyncHttpClient CVE debrief

The AsyncHttpClient library, used for executing HTTP requests and processing responses in Java applications, had a vulnerability prior to versions 3.0.12 and 2.16.1. The library generated the HTTP Digest client nonce (cnonce) using ThreadLocalRandom, which is not a cryptographically secure random source. This could allow an observer to infer the generator state and reduce the protection of the authentication exchange, making it easier for attackers to perform chosen-plaintext and credential precomputation attacks. The issue has been fixed in versions 3.0.12 and 2.16.1.

Vendor
AsyncHttpClient
Product
async-http-client
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Java applications using AsyncHttpClient should assess their exposure and prioritize remediation. This includes verifying the version of AsyncHttpClient in use and ensuring it is updated to a secure version.

Why it matters

The vulnerability in AsyncHttpClient could allow attackers to perform chosen-plaintext and credential precomputation attacks, reducing the protection of the authentication exchange. Defenders should prioritize verifying their inventory and ensuring remediation.

  • Defenders should verify their inventory of applications using AsyncHttpClient to assess exposure.
  • Remediation priority follows from verifying the version of AsyncHttpClient in use and ensuring it is updated to a secure version.
  • Monitoring for potential authentication anomalies could indicate exploitation attempts.

Technical summary

The AsyncHttpClient library generated the HTTP Digest client nonce (cnonce) using ThreadLocalRandom, which is not a cryptographically secure random source. This could allow an observer to infer the generator state and reduce the protection of the authentication exchange. The vulnerability affects versions prior to 3.0.12 and 2.16.1, and defenders should prioritize verifying their inventory and ensuring remediation. The issue has been fixed in versions 3.0.12 and 2.16.1, and defenders should verify the version of AsyncHttpClient in use and ensure it is updated to a secure version.

Defensive priority

Defenders should prioritize verifying their inventory of applications using AsyncHttpClient and ensuring they are running versions 3.0.12 or 2.16.1 or later. Additionally, defenders should monitor for potential authentication anomalies that could indicate exploitation attempts.

Recommended defensive actions

  • Verify inventory of applications using AsyncHttpClient
  • Ensure applications are running versions 3.0.12 or 2.16.1 or later
  • Monitor for potential authentication anomalies
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, its impact, and the fixed versions. However, there is limited information on potential exploitation or victim impact. Defenders should verify the version of AsyncHttpClient in use and ensure it is updated to a secure version. The lack of detailed information on exploitation attempts or victim impact makes it difficult to assess the full scope of the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107283 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107283

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107283 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107283

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random source

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107283.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-mfj3-87qq-382v

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/dca2d90db87f0144ea893a6858dca13c426d06b6

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/e1f5fc88fe211d3f64032c33b91093ba3d5e793d

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.