CVE-2026-107227
Received Received - Intake

AsyncHttpClient WebSocket Permessage-Deflate Heap Exhaustion

Vulnerability report for CVE-2026-107227, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSize do not bound decompressed output. A malicious WebSocket peer can send a small compressed message that expands to a very large Netty buffer and exhausts JVM heap. This issue is fixed in version 3.0.14.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
AsyncHttpClient async-http-client >= 3.0.0, < 3.0.14
AsyncHttpClient async-http-client >= 2.2.0, <= 2.16.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-409 The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the AsyncHttpClient (AHC) library in Java applications. Between versions 2.2.0 and 3.0.14, WebSocket connections with compression enabled do not properly limit decompression of incoming messages. A malicious peer can send a small compressed message that expands into a very large buffer, consuming excessive JVM heap memory and causing a denial of service.

Detection Guidance

Detecting this vulnerability requires checking if your system uses AsyncHttpClient versions between 2.2.0 and 3.0.14. Inspect dependency files like pom.xml or build.gradle for the library version. Monitor for unusual memory consumption or crashes in Java applications using WebSocket connections.

Impact Analysis

If you use AsyncHttpClient versions 2.2.0 to 3.0.13, an attacker could exploit this to crash your application by sending specially crafted WebSocket messages. This could lead to service disruption, application downtime, or potential data loss due to resource exhaustion.

Compliance Impact

This vulnerability could lead to denial-of-service due to excessive memory consumption, potentially disrupting services handling sensitive data. GDPR and HIPAA require safeguards against disruptions that could compromise data availability or integrity, so such vulnerabilities may violate compliance if not addressed.

Mitigation Strategies

Upgrade AsyncHttpClient to version 3.0.14 or later immediately. If upgrading is not possible, disable WebSocket compression in your application configuration. Monitor memory usage and restart affected services to free up exhausted heap space.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107227. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart