Security: AsyncHttpClient/async-http-client
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Connection pool key omits the authenticated principal, so an NTLM or Negotiate connection is reused across identitiesGHSA-vvp4-63h8-v5pm published
Aug 9, 2026 by hyperxproModerate -
Cookie Domain attribute is not checked against the public suffix list, so a cookie can be set for co.ukGHSA-f9m8-cv68-674w published
Aug 9, 2026 by hyperxproModerate -
Digest mutual authentication is switched off by a peer offering qop=auth-intGHSA-qhv6-3pmh-95q4 published
Aug 9, 2026 by hyperxproLow -
Replay to a different host sends the original host request and credentials to the new hostGHSA-jmqq-x5g9-9p2w published
Aug 9, 2026 by hyperxproHigh -
Digest challenge without a usable nonce downgrades to Basic and sends the password in cleartextGHSA-rqf5-2wxv-rjf4 published
Aug 9, 2026 by hyperxproHigh -
Origin credentials sent in cleartext to a proxy that rejects the CONNECTGHSA-v9f2-7rw2-gr2x published
Aug 9, 2026 by hyperxproHigh -
Digest authentication cnonce generated with a non-cryptographic random sourceGHSA-mfj3-87qq-382v published
Aug 9, 2026 by hyperxproLow -
WebSocket handshake continues after a failed Sec-WebSocket-Accept checkGHSA-rwhr-j9rv-85f8 published
Aug 9, 2026 by hyperxproLow -
WebSocket proxy credentials sent to the origin server over a CONNECT tunnelGHSA-3wp9-xfwm-rjjf published
Aug 9, 2026 by hyperxproModerate -
Resumable download index store is created world-readable and follows a planted symlinkGHSA-cf59-3jcr-vfhw published
Aug 9, 2026 by hyperxproModerate
Learn more about advisories related to AsyncHttpClient/async-http-client in the GitHub Advisory Database