Skip to content
#

dependency-security

Here are 3 public repositories matching this topic...

CVE-2026-85721: offline checker for org.asynchttpclient:async-http-client against all 21 repository-level advisories. The GitHub Advisory Database (Dependabot / OSV) lists only 4 of the 17 published on 2026-08-09 - 3.0.12, the version Dependabot recommends, still has 5 (2 high). Fixed in 3.0.13 / 2.16.1.

  • Updated Sep 19, 2026
  • Java

CVE-2026-59903 / CVE-2026-33870: offline checker for io.netty:netty-codec-http - its 14 CVEs plus 9 advisories Netty published on 2026-09-10 that the GitHub Advisory Database (Dependabot) does not list. 4.1.137.Final / 4.2.17.Final is no longer enough; upgrade to 4.1.138.Final / 4.2.18.Final.

  • Updated Sep 19, 2026
  • Java

Add this topic to your repo

To associate your repository with the dependency-security topic, visit your repo's landing page and select "manage topics."

Learn more