Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSize do not bound decompressed output. A malicious WebSocket peer can send a small compressed message that expands to a very large Netty buffer and exhausts JVM heap. This issue is fixed in version 3.0.14.
Published: 2026-10-07
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The AsyncHttpClient (AHC) library contains a flaw where WebSocket permessage‑deflate decompression is unbounded if compression is enabled. Incoming compressed frames are aggregated before the WebSocketClientCompressionHandler inflates them, meaning the webSocketMaxFrameSize and webSocketMaxBufferSize limits do not apply to the decompressed data. A malicious peer can send a tiny compressed payload that expands to a very large buffer and exhaust the JVM heap, a problem that maps to CWE‑400 and CWE‑409. The attacker can thereby force a denial‑of‑service condition for any Java application using AHC.

Affected Systems

Users of the AsyncHttpClient library versions 2.2.0 through 3.0.13 are vulnerable. The issue is fixed in version 3.0.14 and later. Applications that depend on any unpatched AsyncHttpClient instance, whether directly or via a dependency chain, are at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, and though the EPSS score is not available, the category of decompression‑bomb attacks is commonly observed in practice. The vulnerability is exploitable by any attacker who can initiate a WebSocket connection to the affected application and send compressed frames. Because the flaw allows the decompress operation to escape user‑defined limits, an attacker can consume all available memory, resulting in application failure. The vulnerability is not listed in the CISA KEV catalog at this time.

Generated by OpenCVE AI on October 7, 2026 at 23:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to AsyncHttpClient version 3.0.14 or later to apply the vendor’s fix.
  • If an upgrade is not immediately possible, disable permessage‑deflate compression in the WebSocket client configuration to prevent the decompression step from executing.
  • Implement explicit validation of inbound WebSocket frames by limiting decompressed payload safe thresholds to mitigate resource exhaustion.

Generated by OpenCVE AI on October 7, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSize do not bound decompressed output. A malicious WebSocket peer can send a small compressed message that expands to a very large Netty buffer and exhausts JVM heap. This issue is fixed in version 3.0.14.
Title AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompression-bomb denial of service when compression is enabled
Weaknesses CWE-400
CWE-409
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T20:51:04.823Z

Reserved: 2026-10-07T14:34:14.817Z

Link: CVE-2026-107227

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:14.283

Modified: 2026-10-07T21:17:14.283

Link: CVE-2026-107227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:15:08Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)