Threat Advisory

AsyncHttpClient's Decompression Enables Decompression-Bomb Denial of Service

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-85721 is a vulnerability affecting async-http-client versions >= 3.0.0, <= 3.0.11 affecting async-http-client versions >= 2.0.0, <= 2.16.0 in AsyncHttpClient's unbounded HTTP/1.1 response decompression that enables a decompression-bomb denial of service, allowing an attacker to exhaust the client's heap and cause an OutOfMemoryError by sending a small compressed body that inflates without bound in memory. The affected versions are async-http-client 3.x up to and including 3.0.11 and 2.x up to and including 2.16.0, with patches available in versions 3.0.12 and 2.16.1 respectively. This flaw can be exploited via the HTTP/1.1 path without any authentication or user interaction required, making it a critical business risk for organizations relying on AsyncHttpClient.

RECOMMENDATION:

We recommend you to update AsyncHttpClient to version 3.0.12 or 2.16.1.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-85721 is a vulnerability affecting async-http-client versions >= 3.0.0, <= 3.0.11 affecting async-http-client versions >= 2.0.0, <= 2.16.0 in AsyncHttpClient's unbounded HTTP/1.1 response decompression that enables a decompression-bomb denial of service, allowing an attacker to exhaust the client's heap and cause an OutOfMemoryError by sending a small compressed body that inflates without bound in memory. The affected versions are async-http-client 3.x up to and including 3.0.11 and 2.x up to and including 2.16.0, with patches available in versions 3.0.12 and 2.16.1 respectively. This flaw can be exploited via the HTTP/1.1 path without any authentication or user interaction required, making it a critical business risk for organizations relying on AsyncHttpClient.

RECOMMENDATION:

We recommend you to update AsyncHttpClient to version 3.0.12 or 2.16.1.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu