PT-2026-94396 · Unknown · Async Http Client

·

CVE-2026-85721

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions AsyncHttpClient versions 2.0.0 through 2.16.0 AsyncHttpClient versions 3.0.0 through 3.0.11
Description Automatic response decompression on the HTTP/1.1 path uses ChannelManager.newHttpContentDecompressor() to install Http1ContentDecompressor without a cumulative output-size limit. A hostile or compromised server, or an attacker capable of altering a response in transit, can send a small compressed response using gzip, deflate, or snappy that expands across chunks until the client exhausts its heap, resulting in an OutOfMemoryError. This also affects brotli and zstd when optional codecs are present. In versions 3.0.8 through 3.0.10, the HTTP/2 decompressor is also unbounded, meaning switching protocols does not mitigate the issue. The flaw exists because limits applied to individual decode calls are insufficient when a response is delivered as many small chunks; the fix requires tracking total decompressed bytes for the entire response.
Recommendations Update AsyncHttpClient versions 2.0.0 through 2.16.0 to version 2.16.1. Update AsyncHttpClient versions 3.0.0 through 3.0.11 to version 3.0.12 or later. As a temporary workaround for the 3.x line, disable automatic decompression by calling setEnableAutomaticDecompression(false) and perform decompression manually with a defined size limit. As a temporary workaround for the 2.x line, remove the inflater handler through httpAdditionalChannelInitializer. Run the client behind a proxy that caps response sizes to minimize the risk of exploitation.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85721
ECHO-B14E-AC13-29F3
GHSA-7GRG-JCF7-RPMX

Affected Products

Async Http Client