Impact
The AsyncHttpClient (AHC) library contains a flaw where WebSocket permessage‑deflate decompression is unbounded if compression is enabled. Incoming compressed frames are aggregated before the WebSocketClientCompressionHandler inflates them, meaning the webSocketMaxFrameSize and webSocketMaxBufferSize limits do not apply to the decompressed data. A malicious peer can send a tiny compressed payload that expands to a very large buffer and exhaust the JVM heap, a problem that maps to CWE‑400 and CWE‑409. The attacker can thereby force a denial‑of‑service condition for any Java application using AHC.
Affected Systems
Users of the AsyncHttpClient library versions 2.2.0 through 3.0.13 are vulnerable. The issue is fixed in version 3.0.14 and later. Applications that depend on any unpatched AsyncHttpClient instance, whether directly or via a dependency chain, are at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and though the EPSS score is not available, the category of decompression‑bomb attacks is commonly observed in practice. The vulnerability is exploitable by any attacker who can initiate a WebSocket connection to the affected application and send compressed frames. Because the flaw allows the decompress operation to escape user‑defined limits, an attacker can consume all available memory, resulting in application failure. The vulnerability is not listed in the CISA KEV catalog at this time.
OpenCVE Enrichment