Heap Exhaustion Vulnerability in AsyncHttpClient Library by AsyncHttpClient
CVE-2026-85721

7.5HIGH

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-85721?

The AsyncHttpClient library, widely used for executing HTTP requests in Java applications, has a vulnerability that allows an attacker to exploit automatic response decompression. In affected versions, a hostile or compromised server can manipulate the response, leading to an unbounded expansion of decompressed content. Specifically, this vulnerability may cause the client to exhaust its heap memory, resulting in an OutOfMemoryError. This occurs due to missing output-size limits during the decompression process for supported encoding types such as gzip, deflate, and others. Mitigations for this issue have been implemented in versions 2.16.1 and 3.0.12.

Affected Version(s)

async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1

async-http-client >= 3.0.0, < 3.0.12 < 3.0.0, 3.0.12

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.