CVE-2026-107228
Received Received - Intake

Session Fixation in AsyncHttpClient via Cookie Store Override

Vulnerability report for CVE-2026-107228, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
AsyncHttpClient async-http-client >= 3.0.0, < 3.0.14
AsyncHttpClient async-http-client >= 2.1.0, <= 2.16.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The AsyncHttpClient (AHC) library in Java applications executes HTTP requests and processes responses. Between versions 2.1.0 and 3.0.14, the cookie store enabled by default replaces a user-supplied Cookie header if the store has any cookies for the origin. This allows stored cookies from one user to overwrite another user's request cookie in a shared client, causing requests to execute under the wrong session. This bypasses a previous fix for CVE-2024-53990, which only addressed cookies set via addCookie, not those set directly via headers.

Impact Analysis

If you use AsyncHttpClient versions 2.1.0 to 3.0.13 in a multi-user environment, an attacker could manipulate session cookies to impersonate another user. This could lead to unauthorized access to sensitive data or actions performed under a different user's identity.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Organizations using affected versions may face compliance breaches, legal penalties, and reputational damage.

Mitigation Strategies

Upgrade AsyncHttpClient to version 3.0.14 or later to address the vulnerability. Review application code for any direct Cookie header usage and ensure session handling is not affected by cookie store behavior.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107228. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart