Detection of Error Condition Without Action in Async-http-client - #VU142447

 

Detection of Error Condition Without Action in Async-http-client - #VU142447

Published: August 13, 2026


Vulnerability identifier: #VU142447
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-390
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to spoof mutual authentication.

The vulnerability exists due to detection of error condition without action in the auth interceptor when processing SCRAM or Digest mutual-authentication responses. A remote attacker can present an invalid ServerSignature or rspauth value to spoof mutual authentication.

The issue is relevant over non-TLS transport or when the transport is already compromised. If the verification value is omitted entirely or cannot be recovered from the client\'s sent parameters, the response is still accepted.


Affected software

Async-http-client

Remediation

Install security update from vendor's website.

Async-http-client - update to 3.0.12

External References

Related Security Bulletins