Improper Cookie Validation in AsyncHttpClient Library Affects Applications
CVE-2026-107229

4MEDIUM

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-107229?

The AsyncHttpClient library, utilized in Java applications for executing HTTP requests and handling responses, has a vulnerability that arises from insufficient validation of cookie Domain attributes. Versions from 2.16.0 up to 3.0.13 fail to adequately enforce security rules regarding Domain attributes, which can lead to scenarios where cookies set by one origin are sent to another. This misconfiguration allows potential attackers to exploit this flaw to inject malicious cookies, posing risks such as session fixation, especially in applications sharing the same HTTP client across different trust domains. This issue was addressed in version 3.0.14.

Affected Version(s)

async-http-client >= 3.0.11, < 3.0.14 < 3.0.11, 3.0.14

async-http-client >= 2.16.0, <= 2.16.1 <= 2.16.0, 2.16.1

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.