Algorithm Downgrade in Async-http-client - #VU142435
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive credentials.
The vulnerability exists due to selection of a less-secure algorithm during negotiation in parseWWWAuthenticateHeader and parseProxyAuthenticateHeader when processing Digest authentication challenges without a usable nonce. A remote attacker can send a crafted WWW-Authenticate or Proxy-Authenticate challenge to disclose sensitive credentials.
This affects both origin and proxy authentication paths, and user interaction is not required.