Signed Maven provenance and zero runtime dependencies reduce publication and integration concerns. The compiled artifact’s missing README is normal for Maven, while repository-based maintenance could not be verified.
89%
Total Score
100
100
100
All health scores are okay.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-987609 New async-http-client is vulnerable to Cleartext Transmission of Sensitive Information in versions 2.0.0 - 2.16.0 and 3.0.0 - 3.0.11. | 2.0.0 - 2.16.03.0.0 - 3.0.11 | High |
AIKIDO-2026-598331 New async-http-client is vulnerable to Cleartext Transmission of Sensitive Information in versions 2.1.0 - 2.16.0 and 3.0.0 - 3.0.11. | 2.1.0 - 2.16.03.0.0 - 3.0.11 | High |
CVE-2026-85717 org.asynchttpclient:async-http-client is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 3.0.9 - 3.0.11 and 2.14.5 - 2.16.0. | 2.14.5 - 2.16.03.0.9 - 3.0.11 | Medium |
CVE-2026-85720 org.asynchttpclient:async-http-client is vulnerable to Cleartext Transmission of Sensitive Information in versions 3.0.0 - 3.0.11 and 2.0.0 - 2.16.0. | 2.0.0 - 2.16.03.0.0 - 3.0.11 | Medium |
CVE-2026-85721 org.asynchttpclient:async-http-client is vulnerable to Uncontrolled Resource Consumption in versions 3.0.0 - 3.0.11 and 2.0.0 - 2.16.0. | 2.0.0 - 2.16.03.0.0 - 3.0.11 | High |
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.