Improper handling of highly compressed data in Async-http-client - #VU152425
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in the WebSocket permessage-deflate decompression handler when processing compressed WebSocket messages. A remote attacker can send a specially crafted compressed WebSocket message to cause a denial of service.
Only applications that enable WebSocket compression are affected.