« Back to list

Asynchttpclient Project

Asynchttpclient Project Async-http-client: vulnerabilities and CVEs

Asynchttpclient Project Async-http-client has 3 published vulnerabilities, 1 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs3
Last 12 months1
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-45300High (7.4)0.46%—Jun 5, 2026
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak…
CVE-2023-0040High (7.5)0.55%—Jan 18, 2023
Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the result of insufficient validation of HTTP header field values…
CVE-2017-14063High (7.5)3.0%—Aug 31, 2017
Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System1
  2. T1203 Exploitation for Client Execution1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.