Search CVE reports


Toggle filters

1 – 7 of 7 results


CVE-2026-55688

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and from 3.0.0.Beta1 prior to...

1 affected package

async-http-client

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
async-http-client Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45300

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie`...

1 affected package

async-http-client

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
async-http-client Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-40490

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When redirect following is enabled (followRedirect(true)), versions of AsyncHttpClient prior to...

1 affected package

async-http-client

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
async-http-client Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-53990

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When making any HTTP request, the automatically enabled and self-managed CookieStore (aka cookie...

1 affected package

async-http-client

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
async-http-client Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2017-14063

Medium priority
Ignored

Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were...

1 affected package

async-http-client

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
async-http-client Not affected
Show less packages

CVE-2013-7398

Medium priority
Ignored

main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle...

1 affected package

async-http-client

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
async-http-client Not affected
Show less packages

CVE-2013-7397

Medium priority

Some fixes available 1 of 5

Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof...

1 affected package

async-http-client

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
async-http-client Not affected Not affected Not affected
Show less packages