Async Http Client Project maintains a focused HTTP client library that serves as a foundational component in Java-based applications and frameworks, despite its narrow product scope. The vendor's vulnerability disclosures reflect the parsing and protocol-handling demands inherent to HTTP client implementations; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Async Http Client Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45300HIGH The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and | Jun 5, 2026 | 7.4 | 32 | NO | NO |
CVE-2017-14063HIGH Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fra | Aug 31, 2017 | 7.5 | 25 | NO | NO |
CVE-2023-0040HIGH Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the result of insufficient val | Jan 18, 2023 | 7.5 | 24 | NO | NO |
CVE-2013-7398MEDIUM main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of | Jun 24, 2015 | 4.3 | 18 | NO | NO |
CVE-2013-7397MEDIUM Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, whi | Jun 24, 2015 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Async Http Client Project.
Media articles that mention a CVE ID that affects a product developed by Async Http Client Project — matched by CVE ID, not by vendor name.