GHSA-v3r5-pjpm-mwgq · Severity: high · Ecosystem: swift — Async HTTP Client has CRLF Injection vulnerability in HTTP request headers
Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the result of insufficient validation of HTTP header field values before sending them to the network. Users are vulnerable if they pass untrusted data into HTTP header field values without prior sanitisation. Common use-cases here might be to place usernames from a database into HTTP header fields. This vulnerability allows attackers to inject new HTTP header fields, or entirely new requests, into the data stream. This can cause requests to be understood very differently by the remote server than was intended. In general, this is unlikely to result in data disclosure, but it can result in a number of logical errors and other misbehaviours.
Conclusion & alert: CVE-2023-0040 is rated Moderate Risk (50.1/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.36%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-01-27 | 0.34% | 0.36% | +0.02% |
| 2 | 2026-01-20 | 0.11% | 0.34% | +0.23% |
| 3 | 2025-11-21 | — | 0.11% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-v3r5-pjpm-mwgq · Severity: high · Ecosystem: swift — Async HTTP Client has CRLF Injection vulnerability in HTTP request headers
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| asynchttpclient_project | async-http-client | < 1.4.1 | cpe:2.3:a:asynchttpclient_project:async-http-client:*:*:*:*:*:*:*:* |
| asynchttpclient_project | async-http-client | >= 1.5.0, < 1.9.1 | cpe:2.3:a:asynchttpclient_project:async-http-client:*:*:*:*:*:*:*:* |
| asynchttpclient_project | async-http-client | >= 1.10.0, < 1.12.1 | cpe:2.3:a:asynchttpclient_project:async-http-client:*:*:*:*:*:*:*:* |
| asynchttpclient_project | async-http-client | >= 1.13.0, < 1.13.2 | cpe:2.3:a:asynchttpclient_project:async-http-client:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/swift-server/async-http-client/security/advisories/GHSA-v3r5-pjpm-mwgq | Third Party Advisory |