๐Ÿ” CVE Alert

CVE-2026-107227

HIGH 7.5

AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompression-bomb denial of service when compression is enabled

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSize do not bound decompressed output. A malicious WebSocket peer can send a small compressed message that expands to a very large Netty buffer and exhausts JVM heap. This issue is fixed in version 3.0.14.

CWE CWE-400 CWE-409
Vendor asynchttpclient
Product async-http-client
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for asynchttpclient async-http-client

Be the first to know when new high vulnerabilities affecting asynchttpclient async-http-client are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

AsyncHttpClient / async-http-client
>= 3.0.0, < 3.0.14 >= 2.2.0, <= 2.16.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-x8v2-478q-2hvg github.com: https://github.com/AsyncHttpClient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30 github.com: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14