Asynchttpclient
6 CVEs tracked since 2026. Since Sep 2026, none of them reached CISA KEV.
Asynchttpclient CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-09 | 6 | 0 |
Products
The products that kept showing up in Asynchttpclient's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 10 most recently published vulnerabilities affecting Asynchttpclient.
- CVE-2026-85716AsyncHttpClient: SCRAM and Digest mutual-authentication responses are not verified3.7
- CVE-2026-85720AsyncHttpClient: Origin credentials sent to the proxy on the plaintext CONNECT request5.9
- CVE-2026-85718AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial of service5.9
- CVE-2026-85721AsyncHttpClient: Unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service7.5
- CVE-2026-85717AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect target6.8
- CVE-2026-85719AsyncHttpClient: SOCKS proxy credentials sent to the origin server over plaintext HTTP7.5
- CVE-2026-55688AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStore4.0
- CVE-2026-45300async-http-client: Cookie header not stripped on cross-origin redirect7.4
- CVE-2026-40490AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects6.8
- CVE-2024-53990AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s8.1
The record
- Peak rank
- #178 in Sep 2026
- Busiest month shown
- Sep 2026, 6 CVEs
- Months with a KEV entry
- 0 since Sep 2026
- Monthly snapshots
- 1 since 2026