PT-2026-95005 · Unknown · Async Http Client
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AsyncHttpClient versions 3.0.8 through 3.0.11
Description
In the auth interceptor, the functions
processScramAuthenticationInfo() and processAuthenticationInfo() compute the SCRAM ServerSignature or Digest rspauth verification result but fail to act on the outcome. If a mismatch is detected, the library logs the error but continues to deliver the response as authenticated. On non-TLS or compromised transports, this allows a peer that has not proven knowledge of the shared secret to be accepted as the server, removing the client's ability to detect an impostor. Verification is not enforced if the value is absent, if the sent parameters cannot be recovered, or if Digest uses qop=auth-int (a quality-of-protection value that signs the response entity-body, which is not yet read during header processing).Recommendations
Update AsyncHttpClient to version 3.0.12 or later.
As a temporary mitigation, ensure all communications occur over a secure TLS transport to prevent peers from impersonating the server.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Async Http Client