Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie Domain attributes. Missing private-section and default public-suffix rules, absent A-label normalization, locale-sensitive lowercasing, public-suffix host-only handling, and numeric or IP host checks allow one origin to store a cookie later sent to another origin. Applications sharing one client across trust domains can therefore receive attacker-injected cookies and may be exposed to session fixation. This issue is fixed in version 3.0.14.
Published: 2026-10-07
Score: 4 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized session hijacking through cookie injection across domains
Action: Immediate Patch
AI Analysis

Impact

The AsyncHttpClient library performs incomplete validation of cookie Domain attributes from versions 2.16.0 to 3.0.14, allowing cookies set by one origin to be stored and later sent to another origin, especially on public-suffix and IP-address hosts. This flaw can be exploited to inject session cookies or other credential-bearing data, potentially enabling session fixation attacks against Java applications that share a single HTTP client across trust boundaries. The vulnerability is categorized as a partial origin check failure (CWE-1275) and an incomplete input validation issue (CWE-384).

Affected Systems

AsyncHttpClient library, used in Java applications for asynchronous HTTP requests, is affected for releases ranging from 2.16.0 through 3.0.14. Applications that incorporate any of these versions and rely on the default ThreadSafeCookieStore are susceptible; the flaw is patched in 3.0.14 and later releases.

Risk and Exploitability

The CVSS score of 4.0 represents a moderate severity risk. Although no EPSS score is available and the vulnerability is not listed in KEV, the attack vector is feasible for applications that share a single client instance across different trust domains; an attacker controlling a source origin can inject a cookie that will be treated as belonging to a target domain. Remediation through an update mitigates the risk effectively, while failure to patch leaves systems exposed to cookie theft and possible session fixation.

Generated by OpenCVE AI on October 7, 2026 at 23:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AsyncHttpClient to version 3.0.14 or later.
  • Ensure the application does not reuse a single AsyncHttpClient instance across distinct trust domains unless the default cookie store is disabled or replaced with a custom store that enforces strict origin checks.
  • If custom cookie handling is implemented, verify that domain validation logic includes private section, public-suffix, and IP address checks and enables A-label normalization.

Generated by OpenCVE AI on October 7, 2026 at 23:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie Domain attributes. Missing private-section and default public-suffix rules, absent A-label normalization, locale-sensitive lowercasing, public-suffix host-only handling, and numeric or IP host checks allow one origin to store a cookie later sent to another origin. Applications sharing one client across trust domains can therefore receive attacker-injected cookies and may be exposed to session fixation. This issue is fixed in version 3.0.14.
Title AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossing onto public-suffix and IP-address hosts
Weaknesses CWE-1275
CWE-384
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T20:57:36.676Z

Reserved: 2026-10-07T14:34:14.817Z

Link: CVE-2026-107229

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:14.613

Modified: 2026-10-07T21:17:14.613

Link: CVE-2026-107229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:15:08Z

Weaknesses
  • CWE-1275

    Sensitive Cookie with Improper SameSite Attribute

  • CWE-384

    Session Fixation