---
id: CVE-2026-107283
title: >-
  The AsyncHttpClient (AHC) library allows Java applications to easily execute
  HTTP requests and asynchronously process HTTP responses
summary: >-
  The AsyncHttpClient (AHC) library allows Java applications to easily execute
  HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12  and
  2.16.1, Realm.Builder generates the HTTP Digest client nonce with
  ThreadLocalRando…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-338
vendor: AsyncHttpClient
product: async-http-client
affected:
  - 'async-http-client >= 3.0.0, < 3.0.12'
  - 'async-http-client >= 2.0.0, < 2.16.1'
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T22:17:04.327'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107283'
references:
  - url: >-
      https://github.com/AsyncHttpClient/async-http-client/commit/dca2d90db87f0144ea893a6858dca13c426d06b6
    label: security-advisories@github.com
  - url: >-
      https://github.com/AsyncHttpClient/async-http-client/commit/e1f5fc88fe211d3f64032c33b91093ba3d5e793d
    label: security-advisories@github.com
  - url: >-
      https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
    label: security-advisories@github.com
  - url: >-
      https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12
    label: security-advisories@github.com
  - url: >-
      https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-mfj3-87qq-382v
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T21:54:15.104Z'
---

## Overview

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12  and 2.16.1, Realm.Builder generates the HTTP Digest client nonce with ThreadLocalRandom rather than a cryptographically secure random source. Digest relies on an unpredictable cnonce to resist chosen-plaintext and credential precomputation attacks, so an observer able to infer generator state can reduce the protection of the authentication exchange. This issue is fixed in versions 3.0.12 and 2.16.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
