CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2026-85716 LOW

AsyncHttpClient: SCRAM and Digest mutual-authentication responses are not verified

CVSS 3.7 EPSS 0.41% Sep 17, 2026
CVE-2026-85720 MEDIUM

AsyncHttpClient: Origin credentials sent to the proxy on the plaintext CONNECT request

CVSS 5.9 EPSS 0.27% Sep 17, 2026
CVE-2026-85718 MEDIUM

AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial of service

CVSS 5.9 EPSS 0.53% Sep 17, 2026
CVE-2026-85721 HIGH

AsyncHttpClient: Unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service

CVSS 7.5 EPSS 0.63% Sep 17, 2026
CVE-2026-85717 MEDIUM

AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect target

CVSS 6.8 EPSS 0.53% Sep 17, 2026
CVE-2026-85719 HIGH

AsyncHttpClient: SOCKS proxy credentials sent to the origin server over plaintext HTTP

CVSS 7.5 EPSS 0.36% Sep 17, 2026
CVE-2026-55688 MEDIUM

AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStore

CVSS 4.0 EPSS 0.33% Jul 1, 2026
CVE-2026-45300 HIGH

async-http-client: Cookie header not stripped on cross-origin redirect

CVSS 7.4 EPSS 0.46% Jun 5, 2026
CVE-2026-40490 MEDIUM

AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects

CVSS 6.8 EPSS 0.48% Apr 18, 2026
CVE-2024-53990 CRITICAL

AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s

CVSS 9.2 EPSS 0.64% Dec 2, 2024
CVE-2023-0040 HIGH

Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the resul…

CVSS 7.5 EPSS 0.55% Jan 18, 2023
CVE-2017-14063 HIGH

async-http-client: Invalid URL parsing with '?'

CVSS 7.5 EPSS 3.05% Aug 31, 2017
CVE-2013-7398 MEDIUM

async-http-client: missing hostname verification for SSL certificates

CVSS 4.3 EPSS 0.83% Jun 24, 2015
CVE-2013-7397 MEDIUM

async-http-client: SSL/TLS certificate verification is disabled under certain conditions

CVSS 4.3 EPSS 0.99% Jun 24, 2015

Showing 1 to 14 CVEs · page 1