PT-2026-94396 · Unknown · Async Http Client
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
AsyncHttpClient versions 2.0.0 through 2.16.0
AsyncHttpClient versions 3.0.0 through 3.0.11
Description
Automatic response decompression on the HTTP/1.1 path uses
ChannelManager.newHttpContentDecompressor() to install Http1ContentDecompressor without a cumulative output-size limit. A hostile or compromised server, or an attacker capable of altering a response in transit, can send a small compressed response using gzip, deflate, or snappy that expands across chunks until the client exhausts its heap, resulting in an OutOfMemoryError. This also affects brotli and zstd when optional codecs are present. In versions 3.0.8 through 3.0.10, the HTTP/2 decompressor is also unbounded, meaning switching protocols does not mitigate the issue. The flaw exists because limits applied to individual decode calls are insufficient when a response is delivered as many small chunks; the fix requires tracking total decompressed bytes for the entire response.Recommendations
Update AsyncHttpClient versions 2.0.0 through 2.16.0 to version 2.16.1.
Update AsyncHttpClient versions 3.0.0 through 3.0.11 to version 3.0.12 or later.
As a temporary workaround for the 3.x line, disable automatic decompression by calling
setEnableAutomaticDecompression(false) and perform decompression manually with a defined size limit.
As a temporary workaround for the 2.x line, remove the inflater handler through httpAdditionalChannelInitializer.
Run the client behind a proxy that caps response sizes to minimize the risk of exploitation.Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Async Http Client