CVE-2026-107227

Source
https://cve.org/CVERecord?id=CVE-2026-107227
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107227.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107227
Aliases
Downstream
Published
2026-10-07T20:51:04Z
Modified
2026-10-09T07:06:49Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompression-bomb denial of service when compression is enabled
Details

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSize do not bound decompressed output. A malicious WebSocket peer can send a small compressed message that expands to a very large Netty buffer and exhausts JVM heap. This issue is fixed in version 3.0.14.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-400",
        "CWE-409"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107227.json"
}
References

Affected packages

Git / github.com/asynchttpclient/async-http-client

Affected ranges

Type
GIT
Repo
https://github.com/asynchttpclient/async-http-client
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.0.14"
        },
        {
            "introduced": "2.2.0"
        },
        {
            "last_affected": "2.16.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

async-http-client-project-3.*
async-http-client-project-3.0.0
async-http-client-project-3.0.1
async-http-client-project-3.0.10
async-http-client-project-3.0.11
async-http-client-project-3.0.12
async-http-client-project-3.0.13
async-http-client-project-3.0.2
async-http-client-project-3.0.3
async-http-client-project-3.0.4
async-http-client-project-3.0.5
async-http-client-project-3.0.6
async-http-client-project-3.0.7
async-http-client-project-3.0.8
async-http-client-project-3.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107227.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "62633849431880612449914444478636061248",
            "length": 1778
        },
        "id": "CVE-2026-107227-0ae22af6",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java",
            "function": "ChannelManager"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "206915449970480381679608919359816987039",
            "length": 4274
        },
        "id": "CVE-2026-107227-0d94eebf",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/DefaultAsyncHttpClientConfig.java",
            "function": "Builder"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "133492247954785979700358905132929553394",
            "length": 1013
        },
        "id": "CVE-2026-107227-16dd2f2a",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java",
            "function": "updatePipelineForHttpsTunneling"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "64636624619545130653136462790435771734",
                "34371637973553263690196220777057923437",
                "284337539431998822316171873999799606404",
                "213122695546068721203431170606113469611",
                "11988079538396742946649516518828309636",
                "211931129189429044321941855158907955651",
                "208870268393587941746686282794792868875",
                "169997363168566094576795439574165908564",
                "129488906783386848493929895869323767362",
                "299213398370716093646709646843409241964",
                "119078719361094828004427028545599718787",
                "167467989955176180133181594908220183188",
                "64227887390836314449753555046657103995",
                "110819733602089389812168452098355716934",
                "70313504581398254851989994378952549515",
                "99862662644146400988843204338328425254",
                "64227887390836314449753555046657103995",
                "110819733602089389812168452098355716934",
                "70313504581398254851989994378952549515",
                "99862662644146400988843204338328425254"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107227-52bfe1cd",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "147205333760493089916634097330480652242",
            "length": 278
        },
        "id": "CVE-2026-107227-567a39da",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/WebSocketHandler.java",
            "function": "exceptionCaught"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "32905167367208605377775799163742321952",
            "length": 1708
        },
        "id": "CVE-2026-107227-679ebc62",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java",
            "function": "configureBootstraps"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "277462907137128642307332515658166825606",
                "153817502226934423049049370976256473474",
                "175434461313635364041808837607214261143",
                "165625145788168641046317287868465838589",
                "246957905560446635695589822775052876460",
                "49579671093228308218403152535253890280",
                "295928445845309570735364971330945974259",
                "269794014801189886951261389574105881045",
                "91830387801361913406161272824766088498",
                "142672005846007020243971034108577341499",
                "8278868172816929609225108039608529273",
                "284587883851814979699609099466553402229",
                "158267051143667004234483985107263749294",
                "168218289145172575644422692013347160446",
                "210722037477385674301361596093506446958",
                "329871984402229032800894723809866540843",
                "284155093273205633205235971610392882268",
                "300633123961528495984680148479361711072",
                "14038586915400869139976581442647215618",
                "249348388601563714049668940703326344844",
                "137644721238177479887275860761195385833",
                "305893904046476058657335668986250937039",
                "179442674838862836813163331014917484194",
                "230739826450991587639356497538955701616",
                "324706140867179599965288580026896233939",
                "126203686669547524360433565849931644392",
                "8629848389961938453478262940463019710",
                "193988914463149466260316542875473232232",
                "240836668941145953914940990754081293643",
                "89521159268440881987880663019205389198",
                "74608843942381083318177319821339600308",
                "128163853613309043256335567079094153070",
                "195104521791026576634201895373725770988",
                "215848548911028335591922912436883396424"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107227-733cfd7c",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/DefaultAsyncHttpClientConfig.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "26024369513303207292087888145197806032",
                "8680432562235994365666976403680121515",
                "128515585321707940553683049001297692743",
                "7365549684054367923934997386627034430",
                "228916615333922543371759291886978871033",
                "220522223607019346475828728788604731046",
                "268716761841909069358624820763013709910",
                "274231266459575360915763267298599696263",
                "229125371812176119354070324503021315033",
                "159624068906470992503671008732171538278",
                "338680298954052438662341195005992888105",
                "305109536316765344647167759390688219269"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107227-79dbb108",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/WebSocketHandler.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "21756043017926217519549114550014882036",
                "250985907077567986694619176631905965089",
                "59566752877035031845746941922217195201",
                "20815255150061678735631609258527506693",
                "104059582030582928853662739608013791555",
                "6808185833021538695337756396169911773",
                "257317829193147467054909559463845917138"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107227-8b59d07c",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/config/AsyncHttpClientConfigDefaults.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "137664769493454195355622353621007540761",
            "length": 965
        },
        "id": "CVE-2026-107227-a335f823",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java",
            "function": "updatePipelineForHttpTunneling"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "338680585567477214861128048245460086719",
                "218282488849260064431648050686688608159",
                "278427206935271501009821019569470915060"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107227-a8967a0f",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/AsyncHttpClientConfig.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "177321094560400274790912418021972376850",
            "length": 527
        },
        "id": "CVE-2026-107227-e64fdf70",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java",
            "function": "initChannel"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "322118467845321829596335189193302863261",
            "length": 4252
        },
        "id": "CVE-2026-107227-eccd0fc2",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/DefaultAsyncHttpClientConfig.java",
            "function": "DefaultAsyncHttpClientConfig"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "56915641709386240413071006719921485852",
            "length": 2466
        },
        "id": "CVE-2026-107227-febce46c",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/DefaultAsyncHttpClientConfig.java",
            "function": "build"
        }
    }
]
vanir_signatures_modified
"2026-10-09T07:06:49Z"