Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
ECHO-085c-5da2-0e78
  • Echo:Maven/org.asynchttpclient:async-http-client
See record for full details 2 days ago
  • Fix available
ECHO-2935-4daa-b367
  • Echo:Maven/org.asynchttpclient:async-http-client
See record for full details 2 days ago
  • Fix available
ECHO-3fd2-6923-7358
  • Echo:Maven/org.asynchttpclient:async-http-client
See record for full details 2 days ago
  • Fix available
ECHO-7764-b5b5-9fbb
  • Echo:Maven/org.asynchttpclient:async-http-client
See record for full details 2 days ago
  • Fix available
ECHO-b14e-ac13-29f3
  • Echo:Maven/org.asynchttpclient:async-http-client
See record for full details 2 days ago
  • Fix available
GHSA-f8m2-889x-vw4x
  • Maven/org.asynchttpclient:async-http-client
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target 17 Sep
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-xr57-gcx8-52hf
  • Maven/org.asynchttpclient:async-http-client
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request 17 Sep
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-7grg-jcf7-rpmx
  • Maven/org.asynchttpclient:async-http-client
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service 17 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-fj9w-c36g-h5x8
  • Maven/org.asynchttpclient:async-http-client
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses 17 Sep
  • Fix available
  • Severity - 3.7 (Low)
CVE-2026-85716
  • github.com/asynchttpclient/async-http-client
AsyncHttpClient: SCRAM and Digest mutual-authentication responses are not verified 17 Sep
  • Fix available
  • Severity - 3.7 (Low)
CVE-2026-85720
  • github.com/asynchttpclient/async-http-client
AsyncHttpClient: Origin credentials sent to the proxy on the plaintext CONNECT request 17 Sep
  • Fix available
  • Severity - 5.9 (Medium)
CVE-2026-85718
  • github.com/asynchttpclient/async-http-client
AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial of service 17 Sep
  • Fix available
  • Severity - 5.9 (Medium)
CVE-2026-85721
  • github.com/asynchttpclient/async-http-client
AsyncHttpClient: Unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service 17 Sep
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-85717
  • github.com/asynchttpclient/async-http-client
AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect target 17 Sep
  • Fix available
  • Severity - 6.8 (Medium)
CVE-2026-85719
  • github.com/asynchttpclient/async-http-client
AsyncHttpClient: SOCKS proxy credentials sent to the origin server over plaintext HTTP 17 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-m452-q8c9-rg2f
  • Maven/org.asynchttpclient:async-http-client
AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore 26 Aug
  • Fix available
  • Severity - 4.0 (Medium)