PatchSiren cyber security CVE debrief
CVE-2026-107283 AsyncHttpClient CVE debrief
The AsyncHttpClient library, used for executing HTTP requests and processing responses in Java applications, had a vulnerability prior to versions 3.0.12 and 2.16.1. The library generated the HTTP Digest client nonce (cnonce) using ThreadLocalRandom, which is not a cryptographically secure random source. This could allow an observer to infer the generator state and reduce the protection of the authentication exchange, making it easier for attackers to perform chosen-plaintext and credential precomputation attacks. The issue has been fixed in versions 3.0.12 and 2.16.1.
- Vendor
- AsyncHttpClient
- Product
- async-http-client
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Java applications using AsyncHttpClient should assess their exposure and prioritize remediation. This includes verifying the version of AsyncHttpClient in use and ensuring it is updated to a secure version.
Why it matters
The vulnerability in AsyncHttpClient could allow attackers to perform chosen-plaintext and credential precomputation attacks, reducing the protection of the authentication exchange. Defenders should prioritize verifying their inventory and ensuring remediation.
- Defenders should verify their inventory of applications using AsyncHttpClient to assess exposure.
- Remediation priority follows from verifying the version of AsyncHttpClient in use and ensuring it is updated to a secure version.
- Monitoring for potential authentication anomalies could indicate exploitation attempts.
Technical summary
The AsyncHttpClient library generated the HTTP Digest client nonce (cnonce) using ThreadLocalRandom, which is not a cryptographically secure random source. This could allow an observer to infer the generator state and reduce the protection of the authentication exchange. The vulnerability affects versions prior to 3.0.12 and 2.16.1, and defenders should prioritize verifying their inventory and ensuring remediation. The issue has been fixed in versions 3.0.12 and 2.16.1, and defenders should verify the version of AsyncHttpClient in use and ensure it is updated to a secure version.
Defensive priority
Defenders should prioritize verifying their inventory of applications using AsyncHttpClient and ensuring they are running versions 3.0.12 or 2.16.1 or later. Additionally, defenders should monitor for potential authentication anomalies that could indicate exploitation attempts.
Recommended defensive actions
- Verify inventory of applications using AsyncHttpClient
- Ensure applications are running versions 3.0.12 or 2.16.1 or later
- Monitor for potential authentication anomalies
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, its impact, and the fixed versions. However, there is limited information on potential exploitation or victim impact. Defenders should verify the version of AsyncHttpClient in use and ensure it is updated to a secure version. The lack of detailed information on exploitation attempts or victim impact makes it difficult to assess the full scope of the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107283 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107283
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107283 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107283
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random source
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107283.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-mfj3-87qq-382v
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/commit/dca2d90db87f0144ea893a6858dca13c426d06b6
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/commit/e1f5fc88fe211d3f64032c33b91093ba3d5e793d
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.