Heap Exhaustion Vulnerability in AsyncHttpClient Library by AsyncHttpClient
CVE-2026-85721
What is CVE-2026-85721?
The AsyncHttpClient library, widely used for executing HTTP requests in Java applications, has a vulnerability that allows an attacker to exploit automatic response decompression. In affected versions, a hostile or compromised server can manipulate the response, leading to an unbounded expansion of decompressed content. Specifically, this vulnerability may cause the client to exhaust its heap memory, resulting in an OutOfMemoryError. This occurs due to missing output-size limits during the decompression process for supported encoding types such as gzip, deflate, and others. Mitigations for this issue have been implemented in versions 2.16.1 and 3.0.12.
Affected Version(s)
async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1
async-http-client >= 3.0.0, < 3.0.12 < 3.0.0, 3.0.12
