{"id":"CVE-2026-107227","summary":"AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompression-bomb denial of service when compression is enabled","details":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSize do not bound decompressed output. A malicious WebSocket peer can send a small compressed message that expands to a very large Netty buffer and exhausts JVM heap. This issue is fixed in version 3.0.14.","aliases":["GHSA-x8v2-478q-2hvg"],"modified":"2026-10-09T07:06:49.245975026Z","published":"2026-10-07T20:51:04.823Z","database_specific":{"cwe_ids":["CWE-400","CWE-409"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107227.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"},{"type":"ADVISORY","url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-x8v2-478q-2hvg"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107227.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107227"},{"type":"FIX","url":"https://github.com/AsyncHttpClient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asynchttpclient/async-http-client","events":[{"introduced":"9a771c7b40e716ca77a3cad691545b29ff64bfd3"},{"introduced":"e75c218bb6a1ac6b96546eea131c44316f70bc39"},{"fixed":"b61637f30327f314b7693418f12ce141ac6b2b30"},{"fixed":"bec30bb3d27ad13f069f72b37351c61bff3394ff"}],"database_specific":{"extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.0.14"},{"introduced":"2.2.0"},{"last_affected":"2.16.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["async-http-client-project-3.0.13","async-http-client-project-3.0.12","async-http-client-project-3.0.11","async-http-client-project-3.0.10","async-http-client-project-3.0.9","async-http-client-project-3.0.8","async-http-client-project-3.0.7","async-http-client-project-3.0.6","async-http-client-project-3.0.5","async-http-client-project-3.0.4","async-http-client-project-3.0.3","async-http-client-project-3.0.2","async-http-client-project-3.0.1","async-http-client-project-3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107227.json","vanir_signatures":[{"source":"https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30","target":{"file":"client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java","function":"ChannelManager"},"deprecated":false,"digest":{"function_hash":"62633849431880612449914444478636061248","length":1778},"id":"CVE-2026-107227-0ae22af6","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30","target":{"function":"Builder","file":"client/src/main/java/org/asynchttpclient/DefaultAsyncHttpClientConfig.java"},"deprecated":false,"digest":{"function_hash":"206915449970480381679608919359816987039","length":4274},"id":"CVE-2026-107227-0d94eebf","signature_type":"Function"},{"target":{"file":"client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java","function":"updatePipelineForHttpsTunneling"},"deprecated":false,"digest":{"length":1013,"function_hash":"133492247954785979700358905132929553394"},"id":"CVE-2026-107227-16dd2f2a","signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30"},{"target":{"file":"client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java"},"deprecated":false,"digest":{"line_hashes":["64636624619545130653136462790435771734","34371637973553263690196220777057923437","284337539431998822316171873999799606404","213122695546068721203431170606113469611","11988079538396742946649516518828309636","211931129189429044321941855158907955651","208870268393587941746686282794792868875","169997363168566094576795439574165908564","129488906783386848493929895869323767362","299213398370716093646709646843409241964","119078719361094828004427028545599718787","167467989955176180133181594908220183188","64227887390836314449753555046657103995","110819733602089389812168452098355716934","70313504581398254851989994378952549515","99862662644146400988843204338328425254","64227887390836314449753555046657103995","110819733602089389812168452098355716934","70313504581398254851989994378952549515","99862662644146400988843204338328425254"],"threshold":0.9},"id":"CVE-2026-107227-52bfe1cd","signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30"},{"signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30","target":{"file":"client/src/main/java/org/asynchttpclient/netty/handler/WebSocketHandler.java","function":"exceptionCaught"},"deprecated":false,"digest":{"length":278,"function_hash":"147205333760493089916634097330480652242"},"id":"CVE-2026-107227-567a39da","signature_type":"Function"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30","target":{"file":"client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java","function":"configureBootstraps"},"deprecated":false,"digest":{"function_hash":"32905167367208605377775799163742321952","length":1708},"id":"CVE-2026-107227-679ebc62"},{"target":{"file":"client/src/main/java/org/asynchttpclient/DefaultAsyncHttpClientConfig.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["277462907137128642307332515658166825606","153817502226934423049049370976256473474","175434461313635364041808837607214261143","165625145788168641046317287868465838589","246957905560446635695589822775052876460","49579671093228308218403152535253890280","295928445845309570735364971330945974259","269794014801189886951261389574105881045","91830387801361913406161272824766088498","142672005846007020243971034108577341499","8278868172816929609225108039608529273","284587883851814979699609099466553402229","158267051143667004234483985107263749294","168218289145172575644422692013347160446","210722037477385674301361596093506446958","329871984402229032800894723809866540843","284155093273205633205235971610392882268","300633123961528495984680148479361711072","14038586915400869139976581442647215618","249348388601563714049668940703326344844","137644721238177479887275860761195385833","305893904046476058657335668986250937039","179442674838862836813163331014917484194","230739826450991587639356497538955701616","324706140867179599965288580026896233939","126203686669547524360433565849931644392","8629848389961938453478262940463019710","193988914463149466260316542875473232232","240836668941145953914940990754081293643","89521159268440881987880663019205389198","74608843942381083318177319821339600308","128163853613309043256335567079094153070","195104521791026576634201895373725770988","215848548911028335591922912436883396424"]},"id":"CVE-2026-107227-733cfd7c","signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30"},{"source":"https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30","target":{"file":"client/src/main/java/org/asynchttpclient/netty/handler/WebSocketHandler.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["26024369513303207292087888145197806032","8680432562235994365666976403680121515","128515585321707940553683049001297692743","7365549684054367923934997386627034430","228916615333922543371759291886978871033","220522223607019346475828728788604731046","268716761841909069358624820763013709910","274231266459575360915763267298599696263","229125371812176119354070324503021315033","159624068906470992503671008732171538278","338680298954052438662341195005992888105","305109536316765344647167759390688219269"]},"id":"CVE-2026-107227-79dbb108","signature_type":"Line","signature_version":"v1"},{"digest":{"threshold":0.9,"line_hashes":["21756043017926217519549114550014882036","250985907077567986694619176631905965089","59566752877035031845746941922217195201","20815255150061678735631609258527506693","104059582030582928853662739608013791555","6808185833021538695337756396169911773","257317829193147467054909559463845917138"]},"id":"CVE-2026-107227-8b59d07c","signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30","target":{"file":"client/src/main/java/org/asynchttpclient/config/AsyncHttpClientConfigDefaults.java"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"137664769493454195355622353621007540761","length":965},"id":"CVE-2026-107227-a335f823","signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30","target":{"function":"updatePipelineForHttpTunneling","file":"client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java"}},{"source":"https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30","target":{"file":"client/src/main/java/org/asynchttpclient/AsyncHttpClientConfig.java"},"deprecated":false,"digest":{"line_hashes":["338680585567477214861128048245460086719","218282488849260064431648050686688608159","278427206935271501009821019569470915060"],"threshold":0.9},"id":"CVE-2026-107227-a8967a0f","signature_type":"Line","signature_version":"v1"},{"target":{"file":"client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java","function":"initChannel"},"deprecated":false,"digest":{"length":527,"function_hash":"177321094560400274790912418021972376850"},"id":"CVE-2026-107227-e64fdf70","signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30"},{"id":"CVE-2026-107227-eccd0fc2","signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30","target":{"file":"client/src/main/java/org/asynchttpclient/DefaultAsyncHttpClientConfig.java","function":"DefaultAsyncHttpClientConfig"},"deprecated":false,"digest":{"length":4252,"function_hash":"322118467845321829596335189193302863261"}},{"source":"https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30","target":{"file":"client/src/main/java/org/asynchttpclient/DefaultAsyncHttpClientConfig.java","function":"build"},"deprecated":false,"digest":{"function_hash":"56915641709386240413071006719921485852","length":2466},"id":"CVE-2026-107227-febce46c","signature_type":"Function","signature_version":"v1"}],"vanir_signatures_modified":"2026-10-09T07:06:49Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}