Vulnerabilities > Asynchttpclient Project

DATE CVE VULNERABILITY TITLE RISK
2023-01-18 CVE-2023-0040 Injection vulnerability in Asynchttpclient Project Async-Http-Client
Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection.
network
low complexity
asynchttpclient-project CWE-74
7.5
2017-08-31 CVE-2017-14063 Improper Input Validation vulnerability in Asynchttpclient Project Async-Http-Client
Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier.
network
low complexity
asynchttpclient-project CWE-20
7.5