PT-2026-94394 · Unknown · Async Http Client
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
AsyncHttpClient versions 3.0.8 through 3.0.11
Description
A connection permit leak occurs when TLS connection establishment fails before the handshake completes. This happens because the
NettyConnectListener removes the partitionKeyLock permit from NettyResponseFuture before every failure path is bound to the channel closeFuture, which can leave the permit unreleased during an abort. This issue affects clients where maxConnections or maxConnectionsPerHost are set above zero. Repeated failures can lead to a permanent lockout of a host under a per-host limit or drain the shared pool under a global limit, blocking subsequent requests even if no connections are open.Recommendations
Update to version 3.0.12.
Exploit
Fix
Missing Release of Resource after Effective Lifetime
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Async Http Client