Detection of Error Condition Without Action in Async-http-client - #VU142447
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to spoof mutual authentication.
The vulnerability exists due to detection of error condition without action in the auth interceptor when processing SCRAM or Digest mutual-authentication responses. A remote attacker can present an invalid ServerSignature or rspauth value to spoof mutual authentication.
The issue is relevant over non-TLS transport or when the transport is already compromised. If the verification value is omitted entirely or cannot be recovered from the client\'s sent parameters, the response is still accepted.