Search CVE reports


Toggle filters

21 – 30 of 50150 results

Status is adjusted based on your filters.


CVE-2026-107282

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, cross-host request replay updates the current request but leaves...

1 affected package

async-http-client

Package 24.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-107281

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key excludes the authenticated...

1 affected package

async-http-client

Package 24.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-107280

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, ThreadSafeCookieStore validates Domain attributes with domain...

1 affected package

async-http-client

Package 24.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-107279

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In 3.0.12, a peer offering only Digest qop=auth-int causes mutual-authentication verification to...

1 affected package

async-http-client

Package 24.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-107232

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 on 3.x and 2.16.1 on 2.x, the client infers that an HTTP proxy tunnel exists...

1 affected package

async-http-client

Package 24.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-107231

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, Realm.Builder treats a Digest challenge that yields no usable nonce...

1 affected package

async-http-client

Package 24.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-107230

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for...

1 affected package

async-http-client

Package 24.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-107229

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie Domain attributes....

1 affected package

async-http-client

Package 24.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-107228

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly...

1 affected package

async-http-client

Package 24.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-107227

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded...

1 affected package

async-http-client

Package 24.04 LTS
async-http-client Needs evaluation
Show less packages