CVE-2026-107229
Received Received - Intake

Thread-Safety Cookie Handling Flaw in AsyncHttpClient

Vulnerability report for CVE-2026-107229, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie Domain attributes. Missing private-section and default public-suffix rules, absent A-label normalization, locale-sensitive lowercasing, public-suffix host-only handling, and numeric or IP host checks allow one origin to store a cookie later sent to another origin. Applications sharing one client across trust domains can therefore receive attacker-injected cookies and may be exposed to session fixation. This issue is fixed in version 3.0.14.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
AsyncHttpClient async-http-client >= 3.0.11, < 3.0.14
AsyncHttpClient async-http-client >= 2.16.0, <= 2.16.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-384 Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
CWE-1275 The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The AsyncHttpClient (AHC) library in Java has a vulnerability in its ThreadSafeCookieStore from versions 2.16.0 to 3.0.14. It incorrectly validates cookie Domain attributes by missing private-section and default public-suffix rules, lacking A-label normalization, using locale-sensitive lowercasing, improper public-suffix host-only handling, and failing to check numeric or IP hosts. This allows one origin to store a cookie that can later be sent to another origin.

Detection Guidance

This vulnerability affects AsyncHttpClient versions 2.16.0 to 3.0.14 due to improper cookie domain validation. To detect it, check the version of AsyncHttpClient in use with commands like 'mvn dependency:tree' for Maven projects or inspecting the library files directly. If the version is within the affected range, update to version 3.0.14 or later immediately.

Impact Analysis

Applications sharing a single client across different trust domains could receive attacker-injected cookies. This may lead to session fixation attacks where an attacker hijacks user sessions by manipulating cookies.

Compliance Impact

This vulnerability could lead to session fixation or unauthorized cookie injection, potentially allowing attackers to impersonate users or access sensitive data. This may violate GDPR's data protection principles (Article 5) and HIPAA's integrity and confidentiality requirements by enabling unauthorized access to personal or health information.

Mitigation Strategies

Upgrade AsyncHttpClient to version 3.0.14 or later to address the cookie validation flaw. Avoid sharing a single client instance across different trust domains to prevent session fixation risks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107229. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart