THREAT OPS › Threat News › [GHSA] GHSA-7grg-jcf7-rpmx (high) — AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service
[GHSA] GHSA-7grg-jcf7-rpmx (high) — AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service
GHSA-7grg-jcf7-rpmx Severity: high CVE: CVE-2026-85721
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service
### Impact With automatic response decompression enabled (the default), the HTTP/1.1 path decompresses response bodies with no limit on the total output size. A hostile or compromised server, or an attacker who can change a response in
Indicators of compromise
- CVE-2026-85721cve
Original source: https://github.com/advisories/GHSA-7grg-jcf7-rpmx