THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7grg-jcf7-rpmx (high) — AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service

[GHSA] GHSA-7grg-jcf7-rpmx (high) — AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service

medgithub_advisoriesPublished 2026-09-17

GHSA-7grg-jcf7-rpmx Severity: high CVE: CVE-2026-85721

AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service

### Impact With automatic response decompression enabled (the default), the HTTP/1.1 path decompresses response bodies with no limit on the total output size. A hostile or compromised server, or an attacker who can change a response in

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7grg-jcf7-rpmx