CVE-2026-107280
Received Received - Intake

Cookie Injection Risk in AsyncHttpClient

Vulnerability report for CVE-2026-107280, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, ThreadSafeCookieStore validates Domain attributes with domain matching but does not reject public suffixes. A host beneath a suffix such as co.uk can set a cookie for that suffix, after which the shared cookie store sends it to unrelated hosts under the suffix. This can inject or overwrite session-relevant cookie values across origins. This issue is fixed in versions 3.0.13 and 2.16.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
AsyncHttpClient async-http-client >= 3.0.0, < 3.0.13
AsyncHttpClient async-http-client >= 2.0.0, < 2.16.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1275 The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The AsyncHttpClient (AHC) library is used by Java applications to execute HTTP requests and process responses. Versions before 3.0.13 and 2.16.1 have a flaw in the ThreadSafeCookieStore where it fails to reject public suffixes in Domain attributes. This allows a host under a suffix like co.uk to set a cookie for that suffix, which is then shared with unrelated hosts under the same suffix. This can lead to session-relevant cookie values being injected or overwritten across different origins.

Detection Guidance

This vulnerability can be detected by checking the version of AsyncHttpClient in use. If you are using versions prior to 3.0.13 or 2.16.1, the system is vulnerable. Commands to check the version depend on your environment and build tools. For Maven projects, you can use 'mvn dependency:tree' to inspect the version of AsyncHttpClient. For Gradle, use 'gradle dependencies'. Ensure no older versions are present in your dependency tree.

Impact Analysis

This vulnerability can allow attackers to manipulate cookies across different domains under a public suffix. This could lead to session hijacking, unauthorized access to user accounts, or cross-site request forgery (CSRF) attacks. Applications using vulnerable versions of AsyncHttpClient may expose users to risks like data theft or account takeover.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Organizations using affected versions may face compliance breaches, legal penalties, and reputational damage due to potential data exposure.

Mitigation Strategies

Upgrade the AsyncHttpClient library to version 3.0.13 or 2.16.1 or later to address the cookie handling issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107280. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart