Async-Http-Client

AsyncHttpClient · 14 CVEs

CVE-2026-85716
LOW

AsyncHttpClient: SCRAM and Digest mutual-authentication responses are not verified

Sep 17, 2026

CVE-2026-85720
MEDIUM

AsyncHttpClient: Origin credentials sent to the proxy on the plaintext CONNECT request

Sep 17, 2026

CVE-2026-85718
MEDIUM

AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial of service

Sep 17, 2026

CVE-2026-85721
HIGH

AsyncHttpClient: Unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service

Sep 17, 2026

CVE-2026-85717
MEDIUM

AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect target

Sep 17, 2026

CVE-2026-85719
HIGH

AsyncHttpClient: SOCKS proxy credentials sent to the origin server over plaintext HTTP

Sep 17, 2026

CVE-2026-55688
MEDIUM

AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStore

Jul 1, 2026

CVE-2026-45300
HIGH

async-http-client: Cookie header not stripped on cross-origin redirect

Jun 5, 2026

CVE-2026-40490
MEDIUM

AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects

Apr 18, 2026

CVE-2024-53990
CRITICAL

AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s

Dec 2, 2024

CVE-2023-0040
HIGH

Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF inj…

Jan 18, 2023

CVE-2017-14063
HIGH

async-http-client: Invalid URL parsing with '?'

Aug 31, 2017

CVE-2013-7398
MEDIUM

async-http-client: missing hostname verification for SSL certificates

Jun 24, 2015

CVE-2013-7397
MEDIUM

async-http-client: SSL/TLS certificate verification is disabled under certain conditions

Jun 24, 2015

Showing 1 to 14 of 14 CVEs