{"id":"CVE-2026-107279","summary":"AsyncHttpClient: Digest mutual authentication is switched off by a peer offering qop=auth-int","details":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In 3.0.12, a peer offering only Digest qop=auth-int causes mutual-authentication verification to be skipped. AuthenticatorUtils.computeExpectedRspAuth returns no expected value for auth-int, and Interceptors treats that result as unverifiable but nonfatal, so a response with an invalid rspauth value is accepted. A peer that does not know the shared secret can therefore be accepted as the authenticated server. This issue is fixed in version 3.0.13.","aliases":["GHSA-qhv6-3pmh-95q4"],"modified":"2026-10-09T07:06:48.063822948Z","published":"2026-10-07T21:10:26.049Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107279.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-303","CWE-757"]},"references":[{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13"},{"type":"ADVISORY","url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-qhv6-3pmh-95q4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107279.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107279"},{"type":"FIX","url":"https://github.com/AsyncHttpClient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asynchttpclient/async-http-client","events":[{"introduced":"c07038b44e5206375662b46859672e8f1df9f05a"},{"fixed":"a5422493b638226666a1ecb5f82826c7c7845b99"},{"fixed":"35ad15f2f6b1788e3761b0c940a9d7ae3fe64c5d"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"= 3.0.12"},{"last_affected":"= 3.0.12"}]}}],"versions":["= 3.0.12","async-http-client-project-3.0.12"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107279.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["97805854810848179040993990570930928577","59155716211891854800893685778840354194","218947779006849674516431791116176773438","212436144350981974672152115030589471530","99437925918627261752135417521765119024","321477696041553865001592261682065921461","258136773829675064491537336690570149174","150746964226127004859560450704638756189","213398630780031365836845675839359035912","336427295448717052983688971842188076721","30836012204454225470415174060144791855","220884027888050459794073188008898298494","81899338064176927563121070890897858680"],"threshold":0.9},"id":"CVE-2026-107279-164318d7","signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99","target":{"file":"client/src/main/java/org/asynchttpclient/Realm.java"}},{"target":{"file":"client/src/test/java/org/asynchttpclient/DigestMutualAuthTest.java"},"deprecated":false,"digest":{"line_hashes":["177077828873205780994969617059786645382","86598840476591134639806209844553071672","267034189774172212598535447469013910522","99489464915557598464892335076982932180","167164368920557058539313411831231324396","18710410704490642006217915142082633474","74902781695303311979437536956309788858","137097050402874897701490469634140018232","26089143559893565431488737837954284427","129960972384251155284626056429745886034","39804313092321212741217858794539067185","334793853804052214166483715074761543511","188055810702901055824987124101503093428"],"threshold":0.9},"id":"CVE-2026-107279-7f8a0fbd","signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99"},{"id":"CVE-2026-107279-825d07fb","signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99","target":{"file":"client/src/test/java/org/asynchttpclient/RealmTest.java"},"deprecated":false,"digest":{"line_hashes":["328985031380655853533857140646559796327","96415484950934328994772361324125756623","115141405942693491001649820164416439214"],"threshold":0.9}},{"digest":{"function_hash":"87435944507149295447915438907672723011","length":696},"id":"CVE-2026-107279-a110e794","signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99","target":{"function":"authIntRspAuthIsNotEnforcedAgainstAConformantServer","file":"client/src/test/java/org/asynchttpclient/DigestMutualAuthTest.java"},"deprecated":false},{"id":"CVE-2026-107279-a774e57b","signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99","target":{"function":"parseRawQop","file":"client/src/main/java/org/asynchttpclient/Realm.java"},"deprecated":false,"digest":{"function_hash":"184394148728046229348128651366776330215","length":495}}],"vanir_signatures_modified":"2026-10-09T07:06:48Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N"}]}