VulnSea

AsyncHttpClient has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 6.3 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-522 (3). Most affected products: async-http-client (4), org.asynchttpclient:async-http-client (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.3
Publish → KEV
Last 90 days
6 prev 0

Products

  • async-http-client 4
  • org.asynchttpclient:async-http-client 2
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

AsyncHttpClient vulnerabilities

CVEs affecting AsyncHttpClient, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-85716Low· 3.7
4d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM…

SunlitAsyncHttpClient · async-http-clientEPSS 0.32%via NVD
CVE-2026-85720Medium· 5.9
4d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose p…

Sunlitasynchttpclient · org.asynchttpclient:async-http-clientEPSS 0.25%via NVD
CVE-2026-85721High· 7.5PoC
4d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelM…

Midnightasynchttpclient · org.asynchttpclient:async-http-clientEPSS 0.35%via NVD
CVE-2026-85719High· 7.5
4d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the proxy's …

TwilightAsyncHttpClient · async-http-clientEPSS 0.21%via NVD
CVE-2026-85718Medium· 5.9
4d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set above zero leaks one…

SunlitAsyncHttpClient · async-http-clientEPSS 0.32%via NVD
CVE-2026-85717Medium· 6.8
4d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redire…

SunlitAsyncHttpClient · async-http-clientEPSS 0.33%via NVD
AsyncHttpClient vulnerabilities (CVEs) · VulnSea