org.asynchttpclient:async-http-client

Licenses: Apache-2.0

Direct Vulnerabilities

Known vulnerabilities in the org.asynchttpclient:async-http-client package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Protection Mechanism Failure

[2.1.0,3.0.14)
  • H
Cleartext Transmission of Sensitive Information

[2.0.0,2.16.1)[3.0.0,3.0.12)
  • C
Cleartext Transmission of Sensitive Information

[2.0.0,2.16.1)[3.0.0,3.0.13)
  • M
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

[2.0.0,2.16.1)[3.0.0,3.0.12)
  • H
Incorrect Implementation of Authentication Algorithm

[3.0.12,3.0.13)
  • M
Sensitive Cookie with Improper SameSite Attribute

[2.0.0,2.16.1)[3.0.0,3.0.13)
  • C
Origin Validation Error

[2.0.0,3.0.14)
  • H
Cleartext Transmission of Sensitive Information

[2.0.0,2.16.1)[3.0.0.Beta1,3.0.13)
  • H
Origin Validation Error

[2.0.0,2.16.1)[3.0.0,3.0.13)
  • H
Denial of Service (DoS)

[2.2.0,3.0.14)
  • H
Cleartext Transmission of Sensitive Information

[2.0.0,2.16.1)[3.0.0,3.0.12)
  • M
Session Fixation

[2.16.0,3.0.14)
  • H
Improper Authentication

[2.1.0,3.0.14)
  • M
Insufficient Verification of Data Authenticity

[2.0.0,2.16.1)[3.0.0,3.0.12)
  • M
Detection of Error Condition Without Action

[3.0.8,3.0.12)
  • M
Insufficiently Protected Credentials

[2.14.5,2.16.1)[3.0.9,3.0.12)
  • H
Improper Resource Shutdown or Release

[3.0.8,3.0.12)
  • H
Cleartext Transmission of Sensitive Information

[,2.16.1)[3.0.0.Beta1,3.0.12)
  • H
Insufficiently Protected Credentials

[,2.16.1)[3.0.0.Beta1,3.0.12)
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

[,2.16.1)[3.0.0.Beta1,3.0.12)
  • M
Sensitive Cookie with Improper SameSite Attribute

[,2.16.0)[3.0.0.Beta1,3.0.11)
  • M
Exposure of Sensitive System Information to an Unauthorized Control Sphere

[,2.15.0)[3.0.0.Beta1,3.0.10)
  • H
Origin Validation Error

[,2.14.5)[3.0.0.Beta1,3.0.9)
  • H
Improper Authentication

[2.1.0,2.12.4)[3.0.0.Beta1,3.0.1)
  • H
Server Side Request Forgery (SSRF)

[,2.0.35)

Package versions

167 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
3.0.1424 Sep, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
3.0.139 Aug, 2026
  • 1
    C
  • 3
    H
  • 1
    M
  • 0
    L
3.0.129 Aug, 2026
  • 2
    C
  • 6
    H
  • 2
    M
  • 0
    L
3.0.1114 Jun, 2026
  • 2
    C
  • 11
    H
  • 6
    M
  • 0
    L
3.0.1012 May, 2026
  • 2
    C
  • 11
    H
  • 7
    M
  • 0
    L
3.0.912 Apr, 2026
  • 2
    C
  • 11
    H
  • 8
    M
  • 0
    L
3.0.828 Mar, 2026
  • 2
    C
  • 12
    H
  • 7
    M
  • 0
    L
3.0.711 Feb, 2026
  • 2
    C
  • 11
    H
  • 6
    M
  • 0
    L
3.0.631 Dec, 2025
  • 2
    C
  • 11
    H
  • 6
    M
  • 0
    L
3.0.518 Dec, 2025
  • 2
    C
  • 11
    H
  • 6
    M
  • 0
    L