Impact
The AsyncHttpClient library (AHC) exposes a flaw that leaks a connection permit whenever a TLS handshake fails before completion. The leaked permit remains unreleased, causing the per-host or global connection pool to slowly exhaust and eventually block new HTTP requests from the application. This resource exhaustion is considered a denial‑of‑service condition, as the affected host becomes unreachable through AHC while no connections remain open. The issue correlates with CWE‑400 (Uncontrolled Resource Consumption) and CWE‑772 (Unreleased Resource).
Affected Systems
The vulnerability affects AsyncHttpClient versions 3.0.8 through 3.0.12 inclusive. Java applications that use those versions with maxConnections or maxConnectionsPerHost set above zero are susceptible. The default unlimited setting is not impacted. The defect has been fixed in version 3.0.12 and later.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score of less than 1% suggests a very low probability of widespread exploitation. The vulnerability is not in the CISA KEV catalog. An attacker can induce the condition by repeatedly generating TLS handshake failures—such as targeting a host that rejects TLS connections—so that the application’s connection pool becomes permanently locked for that host or globally. Exploitation requires the victim to run an application that includes the affected library; it does not rely on remote exploitation from the attacker’s side, so the risk is limited to the affected application environment.
OpenCVE Enrichment