CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
AsyncHttpClient: SCRAM and Digest mutual-authentication responses are not verified
AsyncHttpClient: Origin credentials sent to the proxy on the plaintext CONNECT request
AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial of service
AsyncHttpClient: Unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service
AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect target
AsyncHttpClient: SOCKS proxy credentials sent to the origin server over plaintext HTTP
AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStore
async-http-client: Cookie header not stripped on cross-origin redirect
AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects
AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s
Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the resul…
async-http-client: Invalid URL parsing with '?'
async-http-client: missing hostname verification for SSL certificates
async-http-client: SSL/TLS certificate verification is disabled under certain conditions
Showing 1 to 14 CVEs · page 1