CVE-2017-14063

HIGH

Async Http Client <2.0.35 - SSRF

Title source: llm

Description

Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL.

Exploits (2)

nomisec STUB
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2017-14063-async-http-client-vulnerable
nomisec WORKING POC
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2017-14063-async-http-client-vulnerable

References (28)

... and 8 more

Scores

CVSS v3 7.5
EPSS 0.0283
EPSS Percentile 86.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-20
Status published
Products (2)
asynchttpclient_project/async-http-client < 2.0.35
org.asynchttpclient/async-http-client 0 - 2.0.35Maven
Published Aug 31, 2017
Tracked Since Feb 18, 2026