CVE-2026-107279: AsyncHttpClient: Digest mutual authentication is switched off by a peer offering qop=auth-int
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In 3.0.12, a peer offering only Digest qop=auth-int causes mutual-authentication verification to be skipped. AuthenticatorUtils.computeExpectedRspAuth returns no expected value for auth-int, and Interceptors treats that result as unverifiable but nonfatal, so a response with an invalid rspauth value is accepted. A peer that does not know the shared secret can therefore be accepted as the authenticated server. This issue is fixed in version 3.0.13.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AsyncHttpClientto a version that resolves this vulnerability.Fixed in 3.0.13
Event History
Frequently Asked Questions
Which deployments are affected?
Java applications using AsyncHttpClient 3.0.12 are affected when they use Digest mutual authentication and communicate with a peer that offers only the Digest qop=auth-int option.
What does an attacker need to exploit this issue?
The attacker needs to act as a peer that offers only qop=auth-int during Digest authentication. The peer does not need to know the shared secret, because an invalid rspauth value can be accepted.
What is the remediation?
Upgrade AsyncHttpClient to version 3.0.13, which fixes the issue.