The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In 3.0.12, a peer offering only Digest qop=auth-int causes mutual-authentication verification to be skipped. AuthenticatorUtils.computeExpectedRspAuth returns no expected value for auth-int, and Interceptors treats that result as unverifiable but nonfatal, so a response with an invalid rspauth value is accepted. A peer that does not know the shared secret can therefore be accepted as the authenticated server. This issue is fixed in version 3.0.13.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-303",
"CWE-757"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107279.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107279.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"97805854810848179040993990570930928577",
"59155716211891854800893685778840354194",
"218947779006849674516431791116176773438",
"212436144350981974672152115030589471530",
"99437925918627261752135417521765119024",
"321477696041553865001592261682065921461",
"258136773829675064491537336690570149174",
"150746964226127004859560450704638756189",
"213398630780031365836845675839359035912",
"336427295448717052983688971842188076721",
"30836012204454225470415174060144791855",
"220884027888050459794073188008898298494",
"81899338064176927563121070890897858680"
],
"threshold": 0.9
},
"id": "CVE-2026-107279-164318d7",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99",
"target": {
"file": "client/src/main/java/org/asynchttpclient/Realm.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"177077828873205780994969617059786645382",
"86598840476591134639806209844553071672",
"267034189774172212598535447469013910522",
"99489464915557598464892335076982932180",
"167164368920557058539313411831231324396",
"18710410704490642006217915142082633474",
"74902781695303311979437536956309788858",
"137097050402874897701490469634140018232",
"26089143559893565431488737837954284427",
"129960972384251155284626056429745886034",
"39804313092321212741217858794539067185",
"334793853804052214166483715074761543511",
"188055810702901055824987124101503093428"
],
"threshold": 0.9
},
"id": "CVE-2026-107279-7f8a0fbd",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99",
"target": {
"file": "client/src/test/java/org/asynchttpclient/DigestMutualAuthTest.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"328985031380655853533857140646559796327",
"96415484950934328994772361324125756623",
"115141405942693491001649820164416439214"
],
"threshold": 0.9
},
"id": "CVE-2026-107279-825d07fb",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99",
"target": {
"file": "client/src/test/java/org/asynchttpclient/RealmTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "87435944507149295447915438907672723011",
"length": 696
},
"id": "CVE-2026-107279-a110e794",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99",
"target": {
"file": "client/src/test/java/org/asynchttpclient/DigestMutualAuthTest.java",
"function": "authIntRspAuthIsNotEnforcedAgainstAConformantServer"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "184394148728046229348128651366776330215",
"length": 495
},
"id": "CVE-2026-107279-a774e57b",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99",
"target": {
"file": "client/src/main/java/org/asynchttpclient/Realm.java",
"function": "parseRawQop"
}
}
]
"2026-10-09T07:06:48Z"