Connection Management Issue in AsyncHttpClient Library by AsyncHttpClient
CVE-2026-85718
5.9MEDIUM
What is CVE-2026-85718?
The AsyncHttpClient library, used for executing HTTP requests and processing responses asynchronously in Java applications, suffers from a connection permit leak. This issue arises when the 'maxConnections' or 'maxConnectionsPerHost' settings are configured to values greater than zero, leading to a scenario where a connection permit is unreleased upon failed TLS connection attempts before handshake completion. This can result in unintended lockout from a host due to the per-host limit or deplete the shared pool under a global limit, consequently impeding future requests. The problem is remedied in AsyncHttpClient version 3.0.12, which resolves these connection management flaws.
Affected Version(s)
async-http-client >= 3.0.8, < 3.0.12
