9 Total advisories
9 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.asynchttpclient:async-http-client is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.8
CVE-2026-85717
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target
LOW 3.7
CVE-2026-85716
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses
HIGH 7.5
CVE-2026-85721
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service
MEDIUM 5.9
CVE-2026-85720
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request
MEDIUM 4.0
CVE-2026-55688
AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore
HIGH 7.4
CVE-2026-45300
async-http-client: Cookie header not stripped on cross-origin redirect
MEDIUM 6.8
CVE-2026-40490
AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects
UNKNOWN
CVE-2024-53990
AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s
HIGH 7.5
CVE-2017-14063
Improper Input Validation in async-http-client
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes