Cookie Injection Vulnerability in AsyncHttpClient Library by AsyncHttpClient
CVE-2026-107280
6.9MEDIUM
What is CVE-2026-107280?
A vulnerability in the AsyncHttpClient library affects how domain attributes are validated in the ThreadSafeCookieStore. This weakness permits hosts under public suffixes, like co.uk, to set cookies that can be sent to unrelated hosts within the same suffix. As a result, there is a potential risk of injecting or overwriting session-relevant cookie values across different origins. Users are encouraged to upgrade to versions 3.0.13 or 2.16.1 to resolve this issue and bolster security.
Affected Version(s)
async-http-client >= 3.0.0, < 3.0.13 < 3.0.0, 3.0.13
async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1
