Connection Management Issue in AsyncHttpClient Library by AsyncHttpClient
CVE-2026-85718

5.9MEDIUM

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-85718?

The AsyncHttpClient library, used for executing HTTP requests and processing responses asynchronously in Java applications, suffers from a connection permit leak. This issue arises when the 'maxConnections' or 'maxConnectionsPerHost' settings are configured to values greater than zero, leading to a scenario where a connection permit is unreleased upon failed TLS connection attempts before handshake completion. This can result in unintended lockout from a host due to the per-host limit or deplete the shared pool under a global limit, consequently impeding future requests. The problem is remedied in AsyncHttpClient version 3.0.12, which resolves these connection management flaws.

Affected Version(s)

async-http-client >= 3.0.8, < 3.0.12

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.