org.asynchttpclient:async-http-client
Maven17 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.asynchttpclient:async-http-clientpage 1 of 1
- CVE-2017-14063HIGHCVSS 7.5EG 7.5fixed in 2.0.352017-08-31
vulnerable: 2.0.0 ... 2.0.9 (71 versions)
Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified i…
- CVE-2024-53990CRITICALCVSS 9.2EG 9.2fixed in 2.12.4 or 3.0.1, by version range2024-12-02
vulnerable: 3.0.0, 3.0.0.Beta1, 3.0.0.Beta2, 3.0.0.Beta3
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When making any HTTP request, the automatically enabled and self-managed CookieStore (aka cookie jar) wil…
- CVE-2026-107227HIGHCVSS 7.5EG 7.5fixed in 3.0.142026-10-07
vulnerable: 3.0.0 ... 3.0.9 (14 versions)
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enab…
- CVE-2026-107228MEDIUMCVSS 6.8EG 6.8fixed in 3.0.142026-10-07
vulnerable: 3.0.0 ... 3.0.9 (14 versions)
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied…
- CVE-2026-107230HIGHCVSS 7.4EG 7.4fixed in 3.0.142026-10-07
vulnerable: 3.0.0 ... 3.0.9 (14 versions)
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, …
- CVE-2026-107231HIGHCVSS 8.7EG 8.7fixed in 3.0.13 or 2.16.1, by version range2026-10-07
vulnerable: 3.0.0 ... 3.0.9 (16 versions)
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, Realm.Builder treats a Digest challenge that yields no usable nonce as a Basi…
- CVE-2026-107280MEDIUMCVSS 6.9EG 6.9fixed in 3.0.13 or 2.16.1, by version range2026-10-07
vulnerable: 3.0.0 ... 3.0.9 (13 versions)
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, ThreadSafeCookieStore validates Domain attributes with domain matching but d…
- CVE-2026-107282CRITICALCVSS 9.4EG 9.4fixed in 3.0.13 or 2.16.1, by version range2026-10-07
vulnerable: 3.0.0 ... 3.0.9 (13 versions)
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, cross-host request replay updates the current request but leaves the target …
- CVE-2026-107283LOWCVSS 3.7EG 3.7fixed in 3.0.12 or 2.16.1, by version range2026-10-07
vulnerable: 3.0.0 ... 3.0.9 (12 versions)
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, Realm.Builder generates the HTTP Digest client nonce with ThreadLocalRandom …
- CVE-2026-107285MEDIUMCVSS 5.9EG 5.9fixed in 3.0.12 or 2.16.1, by version range2026-10-07
vulnerable: 3.0.0 ... 3.0.9 (12 versions)
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newN…
- CVE-2026-40490MEDIUMCVSS 6.8EG 6.8fixed in 3.0.9 or 2.14.5, by version range2026-04-18
vulnerable: 2.0.0 ... 2.9.0 (109 versions)
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When redirect following is enabled (followRedirect(true)), versions of AsyncHttpClient prior to 3.0.9 and…
- CVE-2026-45300HIGHCVSS 7.4EG 7.4fixed in 3.0.10 or 2.15.0, by version range2026-05-18
vulnerable: 2.0.0 ... 2.9.0 (110 versions)
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cr…
- CVE-2026-55688MEDIUMCVSS 4.0EG 4.0fixed in 3.0.11 or 2.16.0, by version range2026-07-01
vulnerable: 2.0.0 ... 2.9.0 (111 versions)
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and from 3.0.0.Beta1 prior to 3.0.11, ThreadSafeCookieStore stored…
- CVE-2026-85716LOWCVSS 3.7EG 3.7fixed in 3.0.122026-09-17
vulnerable: 3.0.10, 3.0.11, 3.0.8, 3.0.9
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM S…
- CVE-2026-85717MEDIUMCVSS 6.8EG 6.8fixed in 3.0.12 or 2.16.1, by version range2026-09-17
vulnerable: 2.14.5, 2.15.0, 2.16.0
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redirect…
- CVE-2026-85720MEDIUMCVSS 5.9EG 5.9fixed in 3.0.12 or 2.16.1, by version range2026-09-17
vulnerable: 2.0.0 ... 2.9.0 (112 versions)
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose pre…
- CVE-2026-85721HIGHCVSS 7.5EG 7.5fixed in 3.0.12 or 2.16.1, by version range2026-09-17
vulnerable: 2.0.0 ... 2.9.0 (112 versions)
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelMan…
Check whether org.asynchttpclient:async-http-client is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.asynchttpclient:async-http-client CVEs against the assets you own.
Book a Demo →