CVE-2026-107283
Received Received - Intake

Realm.Builder HTTP Digest Authentication Weak Nonce in AsyncHttpClient

Vulnerability report for CVE-2026-107283, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, Realm.Builder generates the HTTP Digest client nonce with ThreadLocalRandom rather than a cryptographically secure random source. Digest relies on an unpredictable cnonce to resist chosen-plaintext and credential precomputation attacks, so an observer able to infer generator state can reduce the protection of the authentication exchange. This issue is fixed in versions 3.0.12 and 2.16.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
AsyncHttpClient async-http-client >= 3.0.0, < 3.0.12
AsyncHttpClient async-http-client >= 2.0.0, < 2.16.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-338 The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The AsyncHttpClient (AHC) library in Java versions before 3.0.12 and 2.16.1 generates HTTP Digest client nonce values using ThreadLocalRandom, which is not cryptographically secure. Digest authentication relies on unpredictable nonces to prevent attacks like credential precomputation. Using a weak random source allows observers to infer the nonce generation state and weaken authentication security.

Detection Guidance

This vulnerability is specific to AsyncHttpClient library versions before 3.0.12 and 2.16.1. To detect it, check the library version in your Java application dependencies. Use commands like 'mvn dependency:tree' for Maven or 'gradle dependencies' for Gradle to inspect versions. If using 3.0.12 or later, or 2.16.1 or later, the vulnerability is not present.

Impact Analysis

An attacker who can observe or predict the nonce generation could exploit this to reduce the security of HTTP Digest authentication, potentially enabling credential precomputation attacks or chosen-plaintext attacks. This may lead to unauthorized access if credentials are compromised.

Compliance Impact

This vulnerability does not directly impact GDPR or HIPAA compliance as it relates to authentication security in HTTP Digest requests. The issue involves weak nonce generation in Digest authentication, which could allow credential precomputation attacks but does not inherently violate data protection requirements under these standards.

Mitigation Strategies

Upgrade AsyncHttpClient to version 3.0.12 or 2.16.1 or later to address the insecure nonce generation in Digest authentication.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107283. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart