Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14.
Published: 2026-10-07
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Session Hijacking
Action: Patch Now
AI Analysis

Impact

AsyncHttpClient’s cookie store silently overrides a caller‑supplied Cookie header when the store contributes a cookie for the same origin. This behavior causes a request that explicitly sets a cookie to be executed with a different cookie, resulting in the request running under an unintended session. The underlying weakness is a lack of proper authorization checks on cookie handling, identified as CWE-287.

Affected Systems

AsyncHttpClient (async-http-client) versions 2.1.0 through 3.0.14 inclusive are affected. Applications that use a shared client instance with the default cookie store can experience the cookie override. The problem is resolved in version 3.0.14.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV. The likely attack vector is through client code that sets a Cookie header while a shared client maintains a cookie store; a malicious user can inject a cookie into the store to hijack another user’s session. This inference is based on the description provided, which specifies the mechanism of the override and the resulting session hijacking risk.

Generated by OpenCVE AI on October 7, 2026 at 23:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade async-http-client to 3.0.14 or later where the override bug is fixed
  • If upgrading is not immediately possible, disable the automatic cookie store in the client configuration or avoid using a shared client across users
  • Avoid setting Cookie headers directly in code that shares a client instance; use addCookie for cookie management instead, ensuring isolation

Generated by OpenCVE AI on October 7, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. In the affected execution path, setHeader, addHeader, Cookie header, and CookieStore control or expose the vulnerable behavior. This issue is fixed in version 3.0.14. The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14.

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. In the affected execution path, setHeader, addHeader, Cookie header, and CookieStore control or expose the vulnerable behavior. This issue is fixed in version 3.0.14.
Title AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHeader (Bypass of CVE-2024-53990 Fix)
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T20:57:04.659Z

Reserved: 2026-10-07T14:34:14.817Z

Link: CVE-2026-107228

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:14.457

Modified: 2026-10-07T21:17:14.457

Link: CVE-2026-107228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:15:08Z

Weaknesses