Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set above zero leaks one connection permit whenever TLS connection establishment fails before the handshake completes. NettyConnectListener removes the partitionKeyLock permit from NettyResponseFuture before every failure path is bound to the channel closeFuture, so an abort can leave the permit unreleased. Repeated failures can permanently lock out one host under a per-host limit or drain the shared pool under a global limit, blocking later requests even when no connection remains open. The default unlimited connection setting is not affected. This issue is fixed in version 3.0.12.
Published: 2026-09-17
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

The AsyncHttpClient library (AHC) exposes a flaw that leaks a connection permit whenever a TLS handshake fails before completion. The leaked permit remains unreleased, causing the per-host or global connection pool to slowly exhaust and eventually block new HTTP requests from the application. This resource exhaustion is considered a denial‑of‑service condition, as the affected host becomes unreachable through AHC while no connections remain open. The issue correlates with CWE‑400 (Uncontrolled Resource Consumption) and CWE‑772 (Unreleased Resource).

Affected Systems

The vulnerability affects AsyncHttpClient versions 3.0.8 through 3.0.12 inclusive. Java applications that use those versions with maxConnections or maxConnectionsPerHost set above zero are susceptible. The default unlimited setting is not impacted. The defect has been fixed in version 3.0.12 and later.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, and the EPSS score of less than 1% suggests a very low probability of widespread exploitation. The vulnerability is not in the CISA KEV catalog. An attacker can induce the condition by repeatedly generating TLS handshake failures—such as targeting a host that rejects TLS connections—so that the application’s connection pool becomes permanently locked for that host or globally. Exploitation requires the victim to run an application that includes the affected library; it does not rely on remote exploitation from the attacker’s side, so the risk is limited to the affected application environment.

Generated by OpenCVE AI on September 20, 2026 at 04:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update AsyncHttpClient to version 3.0.12 or later to eliminate the permit leak.
  • If an upgrade is not immediately feasible, configure maxConnections and maxConnectionsPerHost to zero or a minimal value to prevent the pool from being exhausted while using legacy versions.
  • Continuously monitor application logs for repeated TLS handshake failures and adjust connection pool settings as necessary to avoid service disruption.

Generated by OpenCVE AI on September 20, 2026 at 04:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Asynchttpclient Project
Asynchttpclient Project async-http-client
Vendors & Products Asynchttpclient Project
Asynchttpclient Project async-http-client

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set above zero leaks one connection permit whenever TLS connection establishment fails before the handshake completes. NettyConnectListener removes the partitionKeyLock permit from NettyResponseFuture before every failure path is bound to the channel closeFuture, so an abort can leave the permit unreleased. Repeated failures can permanently lock out one host under a per-host limit or drain the shared pool under a global limit, blocking later requests even when no connection remains open. The default unlimited connection setting is not affected. This issue is fixed in version 3.0.12.
Title AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-host denial of service
Weaknesses CWE-400
CWE-772
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Asynchttpclient Project Async-http-client
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T16:40:07.831Z

Reserved: 2026-09-04T14:45:10.648Z

Link: CVE-2026-85718

cve-icon Vulnrichment

Updated: 2026-09-17T16:40:01.509Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:18:16.113

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-85718

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T15:58:40Z

Links: CVE-2026-85718 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:15:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-772

    Missing Release of Resource after Effective Lifetime