GHSA-mfj3-87qq-382v

Suggest an improvement
Source
https://github.com/advisories/GHSA-mfj3-87qq-382v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-mfj3-87qq-382v/GHSA-mfj3-87qq-382v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mfj3-87qq-382v
Aliases
Published
2026-10-08T16:31:04Z
Modified
2026-10-08T16:45:19Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random source
Details

Impact

The client nonce used in HTTP Digest authentication was generated from ThreadLocalRandom, a fast but non-cryptographic pseudorandom number generator. RFC 7616 section 3.3 requires the cnonce to be unpredictable, since it is part of what protects the Digest exchange against chosen-plaintext and precomputation attacks on the credentials. An attacker able to observe or influence enough of the generator's output could reduce the unpredictability the protocol depends on. NTLM (and, on the 3.x line, SCRAM) in this client already use SecureRandom for their own nonces; Digest did not.

Affected versions

  • 3.x: up to and including 3.0.11
  • 2.x: up to and including 2.16.0

Patches

Fixed in 3.0.12 on the 3.x line and in 2.16.1 on the 2.x line. The cnonce is now generated with SecureRandom, matching the other authentication schemes in the client.

Workarounds

None available from application code.

Details

Realm.Builder's cnonce generation seeded its bytes from ThreadLocalRandom.current() rather than a SecureRandom instance.

Database specific
{
    "cwe_ids": [
        "CWE-338"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-08T16:31:04Z",
    "nvd_published_at": "2026-10-07T22:17:04Z",
    "severity": "LOW"
}
References

Affected packages

Maven / org.asynchttpclient:async-http-client

Package

Name
org.asynchttpclient:async-http-client
View open source insights on deps.dev
Purl
pkg:maven/org.asynchttpclient/async-http-client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
3.0.12

Affected versions

3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.0.10
3.0.11

Database specific

last_known_affected_version_range
"<= 3.0.11"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-mfj3-87qq-382v/GHSA-mfj3-87qq-382v.json"

Maven / org.asynchttpclient:async-http-client

Package

Name
org.asynchttpclient:async-http-client
View open source insights on deps.dev
Purl
pkg:maven/org.asynchttpclient/async-http-client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.16.1

Affected versions

2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.1.0-alpha1
2.1.0-alpha2
2.1.0-alpha3
2.1.0-alpha4
2.1.0-alpha5
2.1.0-alpha6
2.1.0-alpha7
2.1.0-alpha8
2.1.0-alpha9
2.1.0-alpha10
2.1.0-alpha11
2.1.0-alpha12
2.1.0-alpha13
2.1.0-alpha14
2.1.0-alpha15
2.1.0-alpha16
2.1.0-alpha17
2.1.0-alpha18
2.1.0-alpha19
2.1.0-alpha20
2.1.0-alpha21
2.1.0-alpha22
2.1.0-alpha23
2.1.0-alpha24
2.1.0-alpha25
2.1.0-alpha26
2.1.0-RC1
2.1.0-RC2
2.1.0-RC3
2.1.0-RC4
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.6.0
2.7.0
2.8.0
2.8.1
2.9.0
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.14.5
2.15.0
2.16.0

Database specific

last_known_affected_version_range
"<= 2.16.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-mfj3-87qq-382v/GHSA-mfj3-87qq-382v.json"