Improper Cookie Validation in AsyncHttpClient Library Affects Applications
CVE-2026-107229
What is CVE-2026-107229?
The AsyncHttpClient library, utilized in Java applications for executing HTTP requests and handling responses, has a vulnerability that arises from insufficient validation of cookie Domain attributes. Versions from 2.16.0 up to 3.0.13 fail to adequately enforce security rules regarding Domain attributes, which can lead to scenarios where cookies set by one origin are sent to another. This misconfiguration allows potential attackers to exploit this flaw to inject malicious cookies, posing risks such as session fixation, especially in applications sharing the same HTTP client across different trust domains. This issue was addressed in version 3.0.14.
Affected Version(s)
async-http-client >= 3.0.11, < 3.0.14 < 3.0.11, 3.0.14
async-http-client >= 2.16.0, <= 2.16.1 <= 2.16.0, 2.16.1
