CVE-2026-107227: AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompression-bomb denial of service when compression is enabled
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSize do not bound decompressed output. A malicious WebSocket peer can send a small compressed message that expands to a very large Netty buffer and exhausts JVM heap. This issue is fixed in version 3.0.14.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AsyncHttpClientto a version that resolves this vulnerability.Fixed in 3.0.14
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service issue?
Java applications using AsyncHttpClient versions from 2.2.0 through 3.0.13 are affected when WebSocket compression is enabled. The issue concerns inbound WebSocket messages from a malicious peer.
What must an attacker be able to do to trigger the issue?
An attacker needs to act as, or control, a WebSocket peer that the application connects to and send a crafted compressed WebSocket message. No authentication or user interaction is required according to the supplied vector.
Do WebSocket frame and buffer size limits prevent exploitation?
No. webSocketMaxFrameSize and webSocketMaxBufferSize do not limit the decompressed output because compressed frames are aggregated before they are inflated.
What is the remediation?
Upgrade AsyncHttpClient to version 3.0.14, which fixes the issue. If an immediate upgrade is not possible, disabling WebSocket compression avoids the affected decompression path.