Security: AsyncHttpClient/async-http-client
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Origin credentials sent in cleartext to a proxy that rejects the CONNECTGHSA-v9f2-7rw2-gr2x published
Aug 9, 2026 by hyperxproHigh -
Digest authentication cnonce generated with a non-cryptographic random sourceGHSA-mfj3-87qq-382v published
Aug 9, 2026 by hyperxproLow -
WebSocket handshake continues after a failed Sec-WebSocket-Accept checkGHSA-rwhr-j9rv-85f8 published
Aug 9, 2026 by hyperxproLow -
WebSocket proxy credentials sent to the origin server over a CONNECT tunnelGHSA-3wp9-xfwm-rjjf published
Aug 9, 2026 by hyperxproModerate -
Resumable download index store is created world-readable and follows a planted symlinkGHSA-cf59-3jcr-vfhw published
Aug 9, 2026 by hyperxproModerate -
URL userinfo credentials sent to the HTTP proxy in the request lineGHSA-qpfv-56x8-xgx4 published
Aug 9, 2026 by hyperxproModerate -
SCRAM and Digest mutual-authentication responses are not verifiedGHSA-fj9w-c36g-h5x8 published
Aug 9, 2026 by hyperxproLow -
Connection permit leak on TLS handshake failure causes per-host denial of serviceGHSA-gcmv-gr82-6m8v published
Aug 9, 2026 by hyperxproModerate -
Client-wide realm credentials re-sent to a cross-origin redirect targetGHSA-f8m2-889x-vw4x published
Aug 9, 2026 by hyperxproModerate -
SOCKS proxy credentials sent to the origin server over plaintext HTTPGHSA-x5w6-vm3f-pp6f published
Aug 9, 2026 by hyperxproHigh
Learn more about advisories related to AsyncHttpClient/async-http-client in the GitHub Advisory Database