Skip to content
Noroxi

asynchttpclient project records

4 published records for vendor asynchttpclient project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
75%
Median publish → KEV
No record has entered KEV

All records

4 records
  • AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s

    CriticalCVSS 9.2No exploitEPSS 1%

    asynchttpclient · async-http-clientDec 2, 2024

  • Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.ne

    HighCVSS 7.5No exploitEPSS 3%

    asynchttpclient project · async-http-clientAug 31, 2017

  • CVE-2023-0040
    30Monitor

    Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection.

    HighCVSS 7.5No exploitEPSS 1%

    asynchttpclient project · async-http-clientJan 18, 2023

  • async-http-client: Cookie header not stripped on cross-origin redirect

    HighCVSS 7.4No exploitEPSS 0%

    asynchttpclient project · async-http-clientJun 5, 2026