Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3045▲ 455 respecto a la semana anterior
Críticas / altas1424▲ 188 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.9) | 0.27% | — | AsynchttpclientAI | 17/9/2026 | 24/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose preemptive origin credentials because NettyRequestFactory and… | |
| Pendiente de análisis | Baja (3.7) | 0.41% | — | AsynchttpclientAI | 17/9/2026 | 24/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM ServerSignature or Digest rspauth verification result but log a mismatch and… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | AsynchttpclientAI | 17/9/2026 | 30/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelManager.newHttpContentDecompressor() to install Http1ContentDecompressor without a… | |
| Pendiente de análisis | Alta (7.5) | 0.36% | — | AsynchttpclientAI | 17/9/2026 | 24/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the proxy's credentials to the origin because NettyRequestFactory and NettyRequestSender… | |
| Pendiente de análisis | Media (5.9) | 0.53% | — | AsynchttpclientAI | 17/9/2026 | 30/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set above zero leaks one connection permit whenever TLS connection establishment fails before the… | |
| Pendiente de análisis | Media (6.8) | 0.53% | — | AsynchttpclientAI | 17/9/2026 | 30/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redirect following can disclose credentials after a cross-origin redirect because the… | |
| Analizada | Crítica (9.1) | 0.33% | — | Apache Httpclient | 11/8/2026 | 24/9/2026 | Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by… | |
| Modificada | Media (5.3) | 0.46% | — | Apache Httpclient | 31/7/2026 | 13/8/2026 | HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue… | |
| Pendiente de análisis | Media (4) | 0.33% | — | AsynchttpclientAI | 1/7/2026 | 6/8/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and from 3.0.0.Beta1 prior to 3.0.11, ThreadSafeCookieStore stored a cookie under the value of its Domain attribute without verifying that the… | |
| Analizada | Alta (7.4) | 0.46% | — | Asynchttpclient Project Async-http-client | 5/6/2026 | 23/7/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin,… | |
| Modificada | Alta (7.3) | 0.70% | — | Apache Httpclient | 22/4/2026 | 9/9/2026 | Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue. | |
| Aplazada | Media (6.8) | 0.48% | — | AsynchttpclientAI | 18/4/2026 | 17/6/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When redirect following is enabled (followRedirect(true)), versions of AsyncHttpClient prior to 3.0.9 and 2.14.5 forward Authorization and Proxy-Authorization headers along with Realm… | |
| Aplazada | Crítica (9.1) | 0.30% | — | Xiaomi Galaxy FDS SDK AndroidAIApache HttpclientAI | 12/2/2026 | 14/7/2026 | Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which accepts any valid… | |
| Analizada | Alta (7.5) | 0.95% | — | Apache HttpclientNetapp Ontap Tools | 24/4/2025 | 17/6/2026 | A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release | |
| Aplazada | Crítica (9.2) | 0.64% | — | AsynchttpclientAI | 2/12/2024 | 17/6/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When making any HTTP request, the automatically enabled and self-managed CookieStore (aka cookie jar) will silently replace explicitly defined Cookies with any that have the same name… | |
| Analizada | Media (4.3) | 0.47% | — | Sensiolabs Httpclient | 6/11/2024 | 17/6/2026 | symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of… | |
| Modificada | Alta (7.5) | 0.55% | — | Asynchttpclient Project Async-http-client | 18/1/2023 | 17/6/2026 | Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the result of insufficient validation of HTTP header field values before sending them to the network. Users are vulnerable if they pass untrusted data into HTTP header… | |
| Modificada | Media (6.5) | 0.66% | — | Jenkins SCM Httpclient | 21/9/2022 | 17/6/2026 | A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 0.46% | — | Jenkins SCM Httpclient | 21/9/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Media (5.3) | 9.0% | — | Apache HttpclientQuarkusOracle Data IntegratorOracle JD Edwards Enterpriseone Orchestrator+13 | 2/12/2020 | 17/6/2026 | Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. | |
| Modificada | Alta (8.8) | 3.0% | — | Sensiolabs HttpclientSensiolabs SymfonyFedoraproject Fedora | 2/9/2020 | 17/6/2026 | In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with… | |
| Modificada | Crítica (9.8) | 3.3% | — | Apache Httpclient | 30/10/2017 | 16/6/2026 | http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification. | |
| Modificada | Alta (7.5) | 3.0% | — | Asynchttpclient Project Async-http-client | 31/8/2017 | 17/6/2026 | Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL. | |
| Modificada | Media (4.3) | 19% | — | Canonical Ubuntu LinuxFedoraproject FedoraApache Httpclient | 27/10/2015 | 17/6/2026 | http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors. | |
| Modificada | Media (4.3) | 5.8% | — | Apache Commons-httpclient | 4/9/2014 | 16/6/2026 | http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with… |