Security: AsyncHttpClient/async-http-client
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
URL userinfo credentials sent to the HTTP proxy in the request lineGHSA-qpfv-56x8-xgx4 published
Aug 9, 2026 by hyperxproModerate -
SCRAM and Digest mutual-authentication responses are not verifiedGHSA-fj9w-c36g-h5x8 published
Aug 9, 2026 by hyperxproLow -
Connection permit leak on TLS handshake failure causes per-host denial of serviceGHSA-gcmv-gr82-6m8v published
Aug 9, 2026 by hyperxproModerate -
Client-wide realm credentials re-sent to a cross-origin redirect targetGHSA-f8m2-889x-vw4x published
Aug 9, 2026 by hyperxproModerate -
SOCKS proxy credentials sent to the origin server over plaintext HTTPGHSA-x5w6-vm3f-pp6f published
Aug 9, 2026 by hyperxproHigh -
Origin credentials sent to the proxy on the plaintext CONNECT requestGHSA-xr57-gcx8-52hf published
Aug 9, 2026 by hyperxproModerate -
Unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of serviceGHSA-7grg-jcf7-rpmx published
Aug 9, 2026 by hyperxproHigh -
Cookie stored for an unrelated domain (cookie tossing) in AsyncHttpClient ThreadSafeCookieStoreGHSA-m452-q8c9-rg2f published
Jun 15, 2026 by hyperxproModerate -
Cookie header not stripped on cross-origin redirectGHSA-fmxf-pm6p-7xgm published
May 12, 2026 by hyperxproHigh -
Authorization credentials leaked to untrusted domains on cross-origin redirectsGHSA-cmxv-58fp-fm3g published
Apr 12, 2026 by hyperxproModerate
Learn more about advisories related to AsyncHttpClient/async-http-client in the GitHub Advisory Database