CVE-2026-107279

Source
https://cve.org/CVERecord?id=CVE-2026-107279
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107279.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107279
Aliases
  • GHSA-qhv6-3pmh-95q4
Downstream
Published
2026-10-07T21:10:26Z
Modified
2026-10-09T07:06:48Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
AsyncHttpClient: Digest mutual authentication is switched off by a peer offering qop=auth-int
Details

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In 3.0.12, a peer offering only Digest qop=auth-int causes mutual-authentication verification to be skipped. AuthenticatorUtils.computeExpectedRspAuth returns no expected value for auth-int, and Interceptors treats that result as unverifiable but nonfatal, so a response with an invalid rspauth value is accepted. A peer that does not know the shared secret can therefore be accepted as the authenticated server. This issue is fixed in version 3.0.13.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-303",
        "CWE-757"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107279.json"
}
References

Affected packages

Git / github.com/asynchttpclient/async-http-client

Affected ranges

Type
GIT
Repo
https://github.com/asynchttpclient/async-http-client
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "= 3.0.12"
        },
        {
            "last_affected": "= 3.0.12"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

= 3.*
= 3.0.12
async-http-client-project-3.*
async-http-client-project-3.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107279.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "97805854810848179040993990570930928577",
                "59155716211891854800893685778840354194",
                "218947779006849674516431791116176773438",
                "212436144350981974672152115030589471530",
                "99437925918627261752135417521765119024",
                "321477696041553865001592261682065921461",
                "258136773829675064491537336690570149174",
                "150746964226127004859560450704638756189",
                "213398630780031365836845675839359035912",
                "336427295448717052983688971842188076721",
                "30836012204454225470415174060144791855",
                "220884027888050459794073188008898298494",
                "81899338064176927563121070890897858680"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107279-164318d7",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/Realm.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "177077828873205780994969617059786645382",
                "86598840476591134639806209844553071672",
                "267034189774172212598535447469013910522",
                "99489464915557598464892335076982932180",
                "167164368920557058539313411831231324396",
                "18710410704490642006217915142082633474",
                "74902781695303311979437536956309788858",
                "137097050402874897701490469634140018232",
                "26089143559893565431488737837954284427",
                "129960972384251155284626056429745886034",
                "39804313092321212741217858794539067185",
                "334793853804052214166483715074761543511",
                "188055810702901055824987124101503093428"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107279-7f8a0fbd",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99",
        "target": {
            "file": "client/src/test/java/org/asynchttpclient/DigestMutualAuthTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "328985031380655853533857140646559796327",
                "96415484950934328994772361324125756623",
                "115141405942693491001649820164416439214"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107279-825d07fb",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99",
        "target": {
            "file": "client/src/test/java/org/asynchttpclient/RealmTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "87435944507149295447915438907672723011",
            "length": 696
        },
        "id": "CVE-2026-107279-a110e794",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99",
        "target": {
            "file": "client/src/test/java/org/asynchttpclient/DigestMutualAuthTest.java",
            "function": "authIntRspAuthIsNotEnforcedAgainstAConformantServer"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "184394148728046229348128651366776330215",
            "length": 495
        },
        "id": "CVE-2026-107279-a774e57b",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/Realm.java",
            "function": "parseRawQop"
        }
    }
]
vanir_signatures_modified
"2026-10-09T07:06:48Z"