Impact
This vulnerability arises because the AsyncHttpClient library performs automatic HTTP/1.1 response decompression without an overall output-size limit. A malicious server or a manipulated network response can send a small compressed payload that expands into a disproportionately large uncompressed body. The decompressor consumes the client’s heap until an OutOfMemoryError is thrown, effectively denying service to the affected application. The flaw maps to resource exhaustion weaknesses.
Affected Systems
The flaw affects the AsyncHttpClient library in versions 2.0.0 through 2.16.0 and 3.0.0 through 3.0.11. The HTTP/2 decompressor was also unbounded in releases 3.0.8 to 3.0.10, meaning simply switching protocols does not mitigate the issue on those releases. The issue was addressed in versions 2.16.1 and 3.0.12, which contain the fixed decompressor implementation.
Risk and Exploitability
The CVSS score of 7.5 indicates a medium to high severity impact, while the EPSS score of less than 1% signals a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious HTTP response delivered over the network; the attacker must control or alter the server response to supply large decompressed data. Exploitation requires the target application to use the vulnerable library and to process external HTTP responses without additional safeguards.
OpenCVE Enrichment
Github GHSA