PT-2026-94394 · Unknown · Async Http Client

·

CVE-2026-85718

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions AsyncHttpClient versions 3.0.8 through 3.0.11
Description A connection permit leak occurs when TLS connection establishment fails before the handshake completes. This happens because the NettyConnectListener removes the partitionKeyLock permit from NettyResponseFuture before every failure path is bound to the channel closeFuture, which can leave the permit unreleased during an abort. This issue affects clients where maxConnections or maxConnectionsPerHost are set above zero. Repeated failures can lead to a permanent lockout of a host under a per-host limit or drain the shared pool under a global limit, blocking subsequent requests even if no connections are open.
Recommendations Update to version 3.0.12.

Exploit

Fix

Missing Release of Resource after Effective Lifetime

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85718
GHSA-GCMV-GR82-6M8V

Affected Products

Async Http Client