Vendor
medium
threat
AsyncHttpClient Unbounded Decompression Denial of Service
1 CVEAsyncHttpClient is vulnerable to a decompression bomb denial of service attack due to unbounded automatic HTTP/1.1 response decompression, potentially leading to heap exhaustion.
exploited
async-http-client +1
denial-of-service
vulnerability
java
1c
high
advisory
async-http-client Cookie Header Leak on Cross-Origin Redirect
2 rules 1 TTPThe async-http-client library leaks `Cookie` headers to cross-origin redirect targets due to missing header stripping in `Redirect30xInterceptor.java`, potentially exposing sensitive information to malicious third parties.
async-http-client +1
cookie
header
redirect
vulnerability
ghsa
CVE-2026-45300
2r
1t