[Git][security-tracker-team/security-tracker][master] Add new issues in async-http-client

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 19 06:50:59 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d5a66e46 by Salvatore Bonaccorso at 2026-09-19T07:50:39+02:00
Add new issues in async-http-client

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1397,17 +1397,44 @@ CVE-2026-85999 (Soup Sieve is a CSS selector library designed to be used with Be
 	NOTE: https://github.com/facelessuser/soupsieve/security/advisories/GHSA-j934-xhv5-fg8f
 	NOTE: Fixed by: https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda (2.9)
 CVE-2026-85721 (The AsyncHttpClient (AHC) library allows Java applications to easily e ...)
-	TODO: check
+	- async-http-client <unfixed>
+	NOTE: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-7grg-jcf7-rpmx
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/5ee2841cbf268bba4a200578be3938ccfc6cc6d6 (async-http-client-project-2.16.1)
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/e9f2f7423e0f6503f529656f2955a1317e56ba14 (async-http-client-project-2.16.1)
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/663a1a91757904b22cfe37e2e6049f1f8ea6ae59 (async-http-client-project-3.0.12)
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/e1871a19972fb496be1b8ac6be11d79e22ff2162 (async-http-client-project-3.0.12)
 CVE-2026-85720 (The AsyncHttpClient (AHC) library allows Java applications to easily e ...)
-	TODO: check
+	- async-http-client <unfixed>
+	NOTE: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-xr57-gcx8-52hf
+	NOTE: https://github.com/AsyncHttpClient/async-http-client/pull/2234
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/9dba5ac988b7e750551f59b2eab550b60ac8a0d6 (async-http-client-project-2.16.1)
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/d07dbc79f5cf378f63c246f6101d7579ace55acc (async-http-client-project-3.0.12)
 CVE-2026-85719 (The AsyncHttpClient (AHC) library allows Java applications to easily e ...)
-	TODO: check
+	- async-http-client <unfixed>
+	NOTE: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-x5w6-vm3f-pp6f
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/718ed2e86126663a88ea3db7a88cbbf93f0069b5 (async-http-client-project-2.16.1)
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/abaa8bd260beda3b85825ff95069ed11eaf4ca8d (async-http-client-project-2.16.1)
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/4d887704dec22027310f66c81503226722e9bd23 (async-http-client-project-3.0.12)
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/be439b2ec773d12d61914c238d3e8eeaa6f0ba21 (async-http-client-project-3.0.12)
 CVE-2026-85718 (The AsyncHttpClient (AHC) library allows Java applications to easily e ...)
-	TODO: check
+	- async-http-client <not-affected> (Vulnerable code not present)
+	NOTE: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-gcmv-gr82-6m8v
+	NOTE: https://github.com/AsyncHttpClient/async-http-client/issues/2189
+	NOTE: https://github.com/AsyncHttpClient/async-http-client/pull/2288
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/64eb57af52a003ae7f29a2f9f4502271bbb138dd (async-http-client-project-3.0.12)
 CVE-2026-85717 (The AsyncHttpClient (AHC) library allows Java applications to easily e ...)
-	TODO: check
+	- async-http-client <not-affected> (Vulnerable code not present)
+	NOTE: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f8m2-889x-vw4x
+	NOTE: https://github.com/AsyncHttpClient/async-http-client/pull/2224
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/43db7bba81430cbd61ec2dc2c7be464e0ff6a0ff (async-http-client-project-2.16.1)
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/b66757bec34def2e9867bb2b77bd848b1112abb4 (async-http-client-project-3.0.12)
 CVE-2026-85716 (The AsyncHttpClient (AHC) library allows Java applications to easily e ...)
-	TODO: check
+	- async-http-client <not-affected> (Vulnerable code not present)
+	NOTE: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-fj9w-c36g-h5x8
+	NOTE: https://github.com/AsyncHttpClient/async-http-client/pull/2235
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/10b3db9910f0bbad2ea3dc7c7553bae12bc4a5e4 (async-http-client-project-3.0.12)
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/685173afea07892462071d966ef6ce5c88cbc66f (async-http-client-project-3.0.12)
+	NOTE: Fixed by: https://github.com/AsyncHttpClient/async-http-client/commit/7fe8700fd5b46c668cee7774624f36b87b9dd32a (async-http-client-project-3.0.12)
 CVE-2026-85715 (ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, E ...)
 	NOT-FOR-US: ExifReader
 CVE-2026-85500 (Authentication Bypass by Primary Weakness vulnerability in team-alembi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d5a66e462986ccc2869f3d980d5ab05a199df7de

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d5a66e462986ccc2869f3d980d5ab05a199df7de
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/1b87d470/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list