The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM ServerSignature or Digest rspauth verification result but log a mismatch and still deliver the response as authenticated. On a non-TLS or compromised transport, a peer that has not proved knowledge of the shared secret can therefore be accepted as the server. The fix rejects a present invalid value and computes Digest rspauth from the Authorization parameters actually sent, but verification remains unenforced when the value is absent, the sent parameters cannot be recovered, or Digest uses qop=auth-int. This issue is fixed in version 3.0.12.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-287",
"CWE-390"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85716.json"
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-85716.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"25998961490987999253194240567021631561",
"125959779378663272433864995486816017518",
"60935536272460781986553696915800818902",
"181522831408715468027066702535044056000",
"42747170057002365036773733267774242929",
"267531618933923187795435929427714707607",
"71753636261294992975341672073860050800",
"24044704016280801602707617374359661835",
"255289143015764342277635733994703281844",
"335064632043830735079911180455655205819",
"152845826495199714951771388418120230086",
"307619707964854580543886339013085000177",
"229947975058879464087287190533247931297",
"58277896884867243934954022884417761138",
"42292268200654642696488215827062729533",
"27255386739205779754761741743155670235",
"53772281494279218312540191297729757298",
"245908520464936020599591926349220810441",
"264042636101123002665026050470270196492",
"160372344692715524003581484678705092167",
"310661915737487113602411158694932388964",
"12552917240032116532823770082504470883",
"227480280248057367171642019704097726726",
"273892810829842030290120069218694497039",
"73643094047071127052389391626090745193",
"230503547499063766878288074325529039487",
"37122835870817210918691559236696188062",
"220008702830918574760446014882817077192",
"317420214037497564360426489367545812917",
"88535554157394865883865021399639351434",
"39181385225898367423203939098363098425",
"24119803702015348933635361194502945264"
],
"threshold": 0.9
},
"id": "CVE-2026-85716-0d006905",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7fe8700fd5b46c668cee7774624f36b87b9dd32a",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "199086188452371555059174653423275437535",
"length": 1128
},
"id": "CVE-2026-85716-11084001",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/685173afea07892462071d966ef6ce5c88cbc66f",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java",
"function": "processScramAuthenticationInfo"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"296603271003009818272025800997750025693",
"7458844023359349659812116549960575741",
"229652407670746004160857992788129392725",
"29447617717266131221555515709788833136",
"223030504690927294151180715813346041335",
"70497256836138823700641650964499456063",
"323217057745809641181000532163976405355",
"294704994817898719792831535637884175324",
"90919995847978189942595376076181993243",
"317803363772821350834430544346430781292",
"198229090032290693761786209097307659148",
"2564585062618728408088305991364323249",
"195474723493506213243739738691382495282",
"298589547551320288449455992296259158151",
"180527184321458503822448185201334282653",
"268211300175068679528271678637470607538",
"181992039836759604792844147075264263450",
"82055611931247380299744779523075142479",
"315462527568025005144455642245324227830",
"225901200381474261679178057267945271688"
],
"threshold": 0.9
},
"id": "CVE-2026-85716-1581f8bd",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7fe8700fd5b46c668cee7774624f36b87b9dd32a",
"target": {
"file": "client/src/main/java/org/asynchttpclient/util/AuthenticatorUtils.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "153315852291279918996205466188823066811",
"length": 32
},
"id": "CVE-2026-85716-15e511ba",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/685173afea07892462071d966ef6ce5c88cbc66f",
"target": {
"file": "client/src/test/java/org/asynchttpclient/ScramAuthTest.java",
"function": "ScramAuthHandler"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "15689866315257572271630719983278634970",
"length": 4332
},
"id": "CVE-2026-85716-21e04886",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/685173afea07892462071d966ef6ce5c88cbc66f",
"target": {
"file": "client/src/test/java/org/asynchttpclient/ScramAuthTest.java",
"function": "handle"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"317806521440611921137039709162923436152",
"283451642370850641880774081748401597284",
"263352890420417881271131946958355410332",
"333512495168840590176855944185694409966",
"288783666119019228395923837905423300622",
"189285532130349899051335605193414534756",
"107944560323591718707782707737298771335",
"80333937796939952311501180020826856345",
"286697754398358631240951912292409927519",
"8650415189045098447338656008230444863",
"330277187783728955438615816642600374716",
"297232533100185109335247041051115657998",
"144861593130602512107547883858395942109",
"40271971126012837254166476681462291484",
"300192979713692193764772549443502560164",
"226061567651223008705422191260479523779",
"255631593516362114008434482364638401288",
"238418098677213391611180015747733068991",
"162214378691405129366435090985835061617",
"35218779277148993905701024264350783530",
"310900019496557494774454050775641211844",
"286926515267791396358918135793846501885",
"269388023387138219682187472964322042575",
"218003569918716336234073370502384836449",
"183032785118570840635049026122437762489",
"287912119742261119213134290356575835208",
"193123032907501870589600386235270049896",
"281399828078983623640041881392292651931",
"253536069999472181876019316817229713233",
"195474723493506213243739738691382495282",
"87166050306333378904010698350559149077",
"155006581967500706890798209200236618575",
"9211634133134859213388291332254536915",
"88664390735470754875360908614500806371",
"159702036614343084901727895277379189173",
"8667484758538106238720508751609681985",
"224791896585102133252416596655761135826",
"203880516125275220809512429772116940272",
"83707733509779705633400413963455016748",
"147023309441437808358418683989491368922",
"273292527114659560490652199856431649160",
"108738142309469071232364016867721193988"
],
"threshold": 0.9
},
"id": "CVE-2026-85716-5256b4b7",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/10b3db9910f0bbad2ea3dc7c7553bae12bc4a5e4",
"target": {
"file": "client/src/main/java/org/asynchttpclient/util/AuthenticatorUtils.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "114685299744255990709820750257144439698",
"length": 85
},
"id": "CVE-2026-85716-6900c3e3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/10b3db9910f0bbad2ea3dc7c7553bae12bc4a5e4",
"target": {
"file": "client/src/main/java/org/asynchttpclient/util/AuthenticatorUtils.java",
"function": "computeRspAuth"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "306480692361590339133715404553532851203",
"length": 782
},
"id": "CVE-2026-85716-7cf6679d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/10b3db9910f0bbad2ea3dc7c7553bae12bc4a5e4",
"target": {
"file": "client/src/main/java/org/asynchttpclient/util/AuthenticatorUtils.java",
"function": "calculateHA1"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"316908811312203254650859862169054780920",
"74224181989790995522852249559055016866",
"64231596575822246759366632321745198341",
"6290967081240770655807471679768992620",
"120633779102563868402960701828313273985",
"128577706220681162036703516009794627061",
"308115874569120609476971489495549683762",
"40925973591202915391464355918037184866",
"165895637468972669223088871716433778727",
"153483112177614183793693039028523414112",
"224746523057440122250390253452432207188",
"272647530840273892409566418632627893113",
"313022023557086929863250173189906983694",
"287906716805110799993098340572894548271",
"95270321669825417549577535255018874323",
"20535880025138166529675328671513762045",
"229901441169362848561058930623037823224",
"279957807728915326224523099873338143486"
],
"threshold": 0.9
},
"id": "CVE-2026-85716-878e60f0",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/10b3db9910f0bbad2ea3dc7c7553bae12bc4a5e4",
"target": {
"file": "client/src/test/java/org/asynchttpclient/DigestMutualAuthTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "235379078358486815871864242133805556967",
"length": 670
},
"id": "CVE-2026-85716-94fed73d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/685173afea07892462071d966ef6ce5c88cbc66f",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java",
"function": "Interceptors"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "299853389610619756685827159861446023906",
"length": 1110
},
"id": "CVE-2026-85716-97ad3520",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/10b3db9910f0bbad2ea3dc7c7553bae12bc4a5e4",
"target": {
"file": "client/src/main/java/org/asynchttpclient/util/AuthenticatorUtils.java",
"function": "computeRspAuth"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"10529248386589025672111084655108689957",
"64101522904316866266469835553471752273",
"13174047182898746740160856863336296805",
"227480280248057367171642019704097726726",
"273892810829842030290120069218694497039",
"112850881962442564298251373231590537547",
"273529580972599949115050376838024806695",
"238706389708962315070549110760252138491",
"173882374665879256261641707258079533710",
"263053843414283702734472226299015541348",
"195996685696717745109127085974003589685",
"288664710115975432051243384034203907239",
"50114858060416663791145822877666383701",
"174626739587343979385885105957745474061",
"338976939582596215770522033010237126245",
"163392888782454123502889559589549254311",
"183752001397347984679810608254020263307",
"302682844717863123409089460281839412915",
"181966110569509341683446378907794895804",
"280126273569746159717483933841555969876",
"178168264693029963169782647383213359586",
"138780156838559339350214148066097192777"
],
"threshold": 0.9
},
"id": "CVE-2026-85716-994f6d23",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/10b3db9910f0bbad2ea3dc7c7553bae12bc4a5e4",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "59410571518939881044314520198313998457",
"length": 1983
},
"id": "CVE-2026-85716-a7868c10",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7fe8700fd5b46c668cee7774624f36b87b9dd32a",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java",
"function": "exitAfterIntercept"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "213987271125178914137426139405967083957",
"length": 1957
},
"id": "CVE-2026-85716-c1926ad3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/685173afea07892462071d966ef6ce5c88cbc66f",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java",
"function": "exitAfterIntercept"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "169697296075029866106475745606556686878",
"length": 762
},
"id": "CVE-2026-85716-c715eaa9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/10b3db9910f0bbad2ea3dc7c7553bae12bc4a5e4",
"target": {
"file": "client/src/test/java/org/asynchttpclient/DigestMutualAuthTest.java",
"function": "invalidRspAuthIsRejected"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "69598249897282640502365621978601936065",
"length": 307
},
"id": "CVE-2026-85716-c7aa426c",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/10b3db9910f0bbad2ea3dc7c7553bae12bc4a5e4",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java",
"function": "sentDigestCnonce"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"150131792797673566715785068230883206859",
"240587028136704347572160405563772757558",
"131735446847728261919867044844142218026",
"142062946346419165060906684556273265766",
"306931962846795495428960205496615483239",
"203161119150590883874547890083755292343",
"176506741617941038833445609233444192893",
"218282564766271943021368286208846620870",
"204453548300256059991212952350282492210",
"53516711448987213035262817754912401551",
"312086828271024008918940530780735223955",
"137211951293250216040610349097625299775",
"96496992209346473132043681037430761793",
"112763078959343928621588584312091386960",
"215314291752340092747309421810334383955",
"123981935835636266621715726772176846053",
"69251420611985895308936398244214302121",
"62478012417044370417017760962034275804",
"243088891284460351359540290395122786406",
"16202576334008206241277181295454207929",
"99972178953563381405279193195961037214",
"168668821164109396692643926320138106448",
"293120412527231481541699981572340718437",
"297735229560394464720769868795954056781",
"248086736556331288719753590192624241685"
],
"threshold": 0.9
},
"id": "CVE-2026-85716-d9a6ab91",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/685173afea07892462071d966ef6ce5c88cbc66f",
"target": {
"file": "client/src/test/java/org/asynchttpclient/ScramAuthTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "232305072670255429032063949095602531639",
"length": 897
},
"id": "CVE-2026-85716-defc2362",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7fe8700fd5b46c668cee7774624f36b87b9dd32a",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java",
"function": "processAuthenticationInfo"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"165401949867917696156288369070393389028",
"109649659254372871995458089365151532922",
"93336293761947466202736365988432567393",
"225264322521742730880217521441102912380",
"248862218337224267538243458646012753332",
"185032981829015444762348410129115960886",
"337562440178289548871912575320492292303"
],
"threshold": 0.9
},
"id": "CVE-2026-85716-df0c2146",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/10b3db9910f0bbad2ea3dc7c7553bae12bc4a5e4",
"target": {
"file": "client/src/test/java/org/asynchttpclient/util/AuthenticatorUtilsTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "221096491229790109207190436780477427200",
"length": 772
},
"id": "CVE-2026-85716-e5e1d39f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7fe8700fd5b46c668cee7774624f36b87b9dd32a",
"target": {
"file": "client/src/main/java/org/asynchttpclient/util/AuthenticatorUtils.java",
"function": "calculateHA1"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "217239178030838392899210232000577058844",
"length": 1092
},
"id": "CVE-2026-85716-e6234092",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7fe8700fd5b46c668cee7774624f36b87b9dd32a",
"target": {
"file": "client/src/main/java/org/asynchttpclient/util/AuthenticatorUtils.java",
"function": "computeRspAuth"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"114268433621461863499791267003027603432",
"288679803082115843398521023645998389435",
"231039946525257727853993411464474613000",
"313043982419165449870289292584736633465",
"130709714753596505079180019359531449139",
"321752487511740242206274904819355620708",
"182566441122876381365995246078891265411",
"62517950465146472494491876880422956681",
"141662077062609249207699818583308020799",
"267544881149312030532364935217910097891",
"217805148296404158710850215420087277368",
"202599756864486849306673441457167095708",
"151046045937622216710210945779279130545",
"256116264487027942397304986164230379894",
"189358672432631012652430973981742824416",
"213666903626823831639057009803433567624",
"38963344833592966829109569167094193739",
"106460883620241285761901541622624504547",
"227400173848888849405208592369485275446",
"216546756796254833458344690167198173087",
"317780376803355693085194508038258747066",
"61174841288505982043628772378846597685",
"275584458793235431516631753917948868185",
"30755624847810429294575233875236231535",
"293952088348675793871517881549484355828",
"339955845164775456544499732658609943062",
"90789018858869856728737291337653292008",
"94896211013091204546313490764737439585",
"104535511619417343044454345658524978632",
"199357894236684993902410960916071814623",
"230761983043563184207745361962692526736",
"172911374451261474282154357267233701421",
"329206088722645096417419881751121252431",
"275907215314777903711380482249542852350",
"319018043943796848736852234748147377650",
"131478560382744479231411496882517832656",
"327957866797464597198443143567771623280",
"128935054347797919132695515683155218914",
"146180279948100525463331854038663650798",
"162911150391187208726157126872153597589",
"52395330550542421835001670018513997117",
"127902684924636259497503358378324527872",
"174646588428782099853790663499796925954",
"132099569554921380567627540817678017660",
"6363392772564248314588188188773450223",
"163449782010842742558448286793120911197",
"194115991999286871248506403315609398807",
"122260614985629486496447965292158240438"
],
"threshold": 0.9
},
"id": "CVE-2026-85716-eae0f310",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/685173afea07892462071d966ef6ce5c88cbc66f",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "180274160912822281215444876858648927757",
"length": 1324
},
"id": "CVE-2026-85716-ec72ea9e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/10b3db9910f0bbad2ea3dc7c7553bae12bc4a5e4",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java",
"function": "processAuthenticationInfo"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "69640319106402614415743637108572206171",
"length": 107
},
"id": "CVE-2026-85716-fe635b1f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/10b3db9910f0bbad2ea3dc7c7553bae12bc4a5e4",
"target": {
"file": "client/src/main/java/org/asynchttpclient/util/AuthenticatorUtils.java",
"function": "calculateHA1"
}
}
]
"2026-09-26T08:03:09Z"