Async-Http-Client
AsyncHttpClient · 14 CVEs
AsyncHttpClient: SCRAM and Digest mutual-authentication responses are not verified
Sep 17, 2026
AsyncHttpClient: Origin credentials sent to the proxy on the plaintext CONNECT request
Sep 17, 2026
AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial of service
Sep 17, 2026
AsyncHttpClient: Unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service
Sep 17, 2026
AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect target
Sep 17, 2026
AsyncHttpClient: SOCKS proxy credentials sent to the origin server over plaintext HTTP
Sep 17, 2026
AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStore
Jul 1, 2026
async-http-client: Cookie header not stripped on cross-origin redirect
Jun 5, 2026
AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects
Apr 18, 2026
AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s
Dec 2, 2024
Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF inj…
Jan 18, 2023
async-http-client: Invalid URL parsing with '?'
Aug 31, 2017
async-http-client: missing hostname verification for SSL certificates
Jun 24, 2015
async-http-client: SSL/TLS certificate verification is disabled under certain conditions
Jun 24, 2015
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-85716 | AsyncHttpClient: SCRAM and Digest mutual-authentication responses are not verified | LOW | 0.41% | Sep 17, 2026 |
| CVE-2026-85720 | AsyncHttpClient: Origin credentials sent to the proxy on the plaintext CONNECT request | MEDIUM | 0.27% | Sep 17, 2026 |
| CVE-2026-85718 | AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial of service | MEDIUM | 0.53% | Sep 17, 2026 |
| CVE-2026-85721 | AsyncHttpClient: Unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service | HIGH | 0.63% | Sep 17, 2026 |
| CVE-2026-85717 | AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect target | MEDIUM | 0.53% | Sep 17, 2026 |
| CVE-2026-85719 | AsyncHttpClient: SOCKS proxy credentials sent to the origin server over plaintext HTTP | HIGH | 0.36% | Sep 17, 2026 |
| CVE-2026-55688 | AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStore | MEDIUM | 0.33% | Jul 1, 2026 |
| CVE-2026-45300 | async-http-client: Cookie header not stripped on cross-origin redirect | HIGH | 0.46% | Jun 5, 2026 |
| CVE-2026-40490 | AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects | MEDIUM | 0.48% | Apr 18, 2026 |
| CVE-2024-53990 | AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s | CRITICAL | 0.64% | Dec 2, 2024 |
| CVE-2023-0040 | Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the resul… | HIGH | 0.55% | Jan 18, 2023 |
| CVE-2017-14063 | async-http-client: Invalid URL parsing with '?' | HIGH | 3.05% | Aug 31, 2017 |
| CVE-2013-7398 | async-http-client: missing hostname verification for SSL certificates | MEDIUM | 0.83% | Jun 24, 2015 |
| CVE-2013-7397 | async-http-client: SSL/TLS certificate verification is disabled under certain conditions | MEDIUM | 0.99% | Jun 24, 2015 |
Showing 1 to 14 of 14 CVEs