Asynchttpclient Project maintains a narrowly scoped asynchronous HTTP client library that sees use across Java-based applications, with its disclosed vulnerabilities clustering around input-handling and protocol-level weaknesses such as CRLF injection, improper input validation, and exposure of sensitive information. Treat this as a compact vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Asynchttpclient Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45300HIGH The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and | Jun 5, 2026 | 7.4 | 30 | NO | NO |
CVE-2017-14063HIGH Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fra | Aug 31, 2017 | 7.5 | 25 | NO | NO |
CVE-2023-0040HIGH Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the result of insufficient val | Jan 18, 2023 | 7.5 | 24 | NO | NO |
CVE-2013-7398MEDIUM main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of | Jun 24, 2015 | 4.3 | 18 | NO | NO |
CVE-2013-7397MEDIUM Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, whi | Jun 24, 2015 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Asynchttpclient Project.
Media articles that mention a CVE ID that affects a product developed by Asynchttpclient Project — matched by CVE ID, not by vendor name.