Cookie Injection Vulnerability in AsyncHttpClient Library by AsyncHttpClient
CVE-2026-107280

6.9MEDIUM

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-107280?

A vulnerability in the AsyncHttpClient library affects how domain attributes are validated in the ThreadSafeCookieStore. This weakness permits hosts under public suffixes, like co.uk, to set cookies that can be sent to unrelated hosts within the same suffix. As a result, there is a potential risk of injecting or overwriting session-relevant cookie values across different origins. Users are encouraged to upgrade to versions 3.0.13 or 2.16.1 to resolve this issue and bolster security.

Affected Version(s)

async-http-client >= 3.0.0, < 3.0.13 < 3.0.0, 3.0.13

async-http-client >= 2.0.0, < 2.16.1 < 2.0.0, 2.16.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.