THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fj9w-c36g-h5x8 (low) — AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses

[GHSA] GHSA-fj9w-c36g-h5x8 (low) — AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses

medgithub_advisoriesPublished 2026-09-17

GHSA-fj9w-c36g-h5x8 Severity: low CVE: CVE-2026-85716

AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses

### Impact For SCRAM, and for Digest with mutual authentication, the client computes the server's verification value (the SCRAM ServerSignature, or the Digest rspauth) but does not act on the result. If the value is present and does not verify, the client only log

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fj9w-c36g-h5x8