PT-2026-95005 · Unknown · Async Http Client

·

CVE-2026-85716

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions AsyncHttpClient versions 3.0.8 through 3.0.11
Description In the auth interceptor, the functions processScramAuthenticationInfo() and processAuthenticationInfo() compute the SCRAM ServerSignature or Digest rspauth verification result but fail to act on the outcome. If a mismatch is detected, the library logs the error but continues to deliver the response as authenticated. On non-TLS or compromised transports, this allows a peer that has not proven knowledge of the shared secret to be accepted as the server, removing the client's ability to detect an impostor. Verification is not enforced if the value is absent, if the sent parameters cannot be recovered, or if Digest uses qop=auth-int (a quality-of-protection value that signs the response entity-body, which is not yet read during header processing).
Recommendations Update AsyncHttpClient to version 3.0.12 or later. As a temporary mitigation, ensure all communications occur over a secure TLS transport to prevent peers from impersonating the server.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85716
GHSA-FJ9W-C36G-H5X8

Affected Products

Async Http Client