THREAT OPS › Threat News › [GHSA] GHSA-fj9w-c36g-h5x8 (low) — AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses
[GHSA] GHSA-fj9w-c36g-h5x8 (low) — AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses
GHSA-fj9w-c36g-h5x8 Severity: low CVE: CVE-2026-85716
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses
### Impact For SCRAM, and for Digest with mutual authentication, the client computes the server's verification value (the SCRAM ServerSignature, or the Digest rspauth) but does not act on the result. If the value is present and does not verify, the client only log
Indicators of compromise
- CVE-2026-85716cve
Original source: https://github.com/advisories/GHSA-fj9w-c36g-h5x8