Security: AsyncHttpClient/async-http-client
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Pooled connections can still be shared across NTLM, Negotiate and proxy loginsGHSA-v2j5-22fr-j62r published
Sep 24, 2026 by hyperxproHigh -
Incomplete origin checks in the default cookie store allow cookie tossing onto public-suffix and IP-address hostsGHSA-qjr7-w8pj-pmv9 published
Sep 24, 2026 by hyperxproModerate -
Unbounded WebSocket permessage-deflate decompression enables a decompression-bomb denial of service when compression is enabledGHSA-x8v2-478q-2hvg published
Sep 24, 2026 by hyperxproHigh -
Cookies received over plaintext HTTP can plant, overwrite or delete Secure cookies set over HTTPSGHSA-p2jm-6hj6-9rjg published
Sep 24, 2026 by hyperxproModerate -
AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHeader (Bypass of CVE-2024-53990 Fix)GHSA-2jwh-9rmr-j4xf published
Sep 24, 2026 by hyperxproModerate -
Connection pool key omits the authenticated principal, so an NTLM or Negotiate connection is reused across identitiesGHSA-vvp4-63h8-v5pm published
Aug 9, 2026 by hyperxproModerate -
Cookie Domain attribute is not checked against the public suffix list, so a cookie can be set for co.ukGHSA-f9m8-cv68-674w published
Aug 9, 2026 by hyperxproModerate -
Digest mutual authentication is switched off by a peer offering qop=auth-intGHSA-qhv6-3pmh-95q4 published
Aug 9, 2026 by hyperxproLow -
Replay to a different host sends the original host request and credentials to the new hostGHSA-jmqq-x5g9-9p2w published
Aug 9, 2026 by hyperxproHigh -
Digest challenge without a usable nonce downgrades to Basic and sends the password in cleartextGHSA-rqf5-2wxv-rjf4 published
Aug 9, 2026 by hyperxproHigh
Learn more about advisories related to AsyncHttpClient/async-http-client in the GitHub Advisory Database