CVE-2017-14063
HIGHAsync Http Client <2.0.35 - SSRF
Title source: llmDescription
Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL.
Exploits (2)
nomisec
STUB
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2017-14063-async-http-client-vulnerable
nomisec
WORKING POC
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2017-14063-async-http-client-vulnerable
References (28)
... and 8 more
Scores
CVSS v3
7.5
EPSS
0.0283
EPSS Percentile
86.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-20
Status
published
Products (2)
asynchttpclient_project/async-http-client
< 2.0.35
org.asynchttpclient/async-http-client
0 - 2.0.35Maven
Published
Aug 31, 2017
Tracked Since
Feb 18, 2026