Vulnerability GHSA-mfj3-87qq-382v

Low Risk
LOW RISK
CVSS Score: 3.7
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
6 hours ago
October 08, 2026 at 04:31 PM UTC
AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random source
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.0
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.0

Summary

AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random source

Details

Impact

The client nonce used in HTTP Digest authentication was generated from ThreadLocalRandom, a fast but non-cryptographic pseudorandom number generator. RFC 7616 section 3.3 requires the cnonce to be unpredictable, since it is part of what protects the Digest exchange against chosen-plaintext and precomputation attacks on the credentials. An attacker able to observe or influence enough of the generator's output could reduce the unpredictability the protocol depends on. NTLM (and, on the 3.x line, SCRAM) in this client already use SecureRandom for their own nonces; Digest did not.

Affected versions

  • 3.x: up to and including 3.0.11
  • 2.x: up to and including 2.16.0

Patches

Fixed in 3.0.12 on the 3.x line and in 2.16.1 on the 2.x line. The cnonce is now generated with SecureRandom, matching the other authentication schemes in the client.

Workarounds

None available from application code.

Details

Realm.Builder's cnonce generation seeded its bytes from ThreadLocalRandom.current() rather than a SecureRandom instance.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Medium Risk
6 hours ago
AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHeader (Bypass of CVE-2024-53990 Fix)
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-2jwh-9rmr-j4xf
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-2jwh-9rmr-j4xf
Medium Risk
6 hours ago
AsyncHttpClient: Cookies received over plaintext HTTP can plant, overwrite or delete Secure cookies set over HTTPS
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-p2jm-6hj6-9rjg
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-p2jm-6hj6-9rjg
High Risk
6 hours ago
AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompression-bomb denial of service when compression is enabled
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-x8v2-478q-2hvg
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-x8v2-478q-2hvg
High Risk
6 hours ago
AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-v2j5-22fr-j62r
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-v2j5-22fr-j62r
Medium Risk
6 hours ago
AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tunnel
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.0 GHSA-3wp9-xfwm-rjjf
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.0 GHSA-3wp9-xfwm-rjjf
View all vulnerabilities for these packages

Timeline

Published
6 hours ago
October 08, 2026 at 04:31 PM UTC
Fixed (3.0.12)
Unknown
Unknown
Fixed (2.16.1)
Unknown
Unknown
Last Modified
6 hours ago
October 08, 2026 at 04:45 PM UTC