Org.asynchttpclient:async-http-client
This hub aggregates every CVE we track for Org.asynchttpclient:async-http-client, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
2
CVEs tracked
0
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2
Monthly trend
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 2 most recently published vulnerabilities affecting Org.asynchttpclient:async-http-client.
- CVE-2024-53990AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s8.1
- CVE-2017-14063Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier....7.5
Product normalization is registry-driven with AI assist and human review. How it works