Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, ThreadSafeCookieStore validates Domain attributes with domain matching but does not reject public suffixes. A host beneath a suffix such as co.uk can set a cookie for that suffix, after which the shared cookie store sends it to unrelated hosts under the suffix. This can inject or overwrite session-relevant cookie values across origins. This issue is fixed in versions 3.0.13 and 2.16.1.
Published: 2026-10-07
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Session hijacking via cross-origin cookie injection
Action: Apply Update
AI Analysis

Impact

The AsyncHttpClient library did not filter cookie domain attributes against the public suffix list before versions 3.0.13 and 2.16.1. An attacker able to make the library send a response containing a Set‑Cookie header for a domain like co.uk could write a cookie that is accepted for any host in that suffix. The shared cookie store would then forward that cookie to unrelated hosts under the same suffix, enabling the attacker to inject or overwrite session‑related cookie values across origins, potentially hijacking user sessions or injecting data manipulated across different services.

Affected Systems

This flaw affects the AsyncHttpClient component of Java applications that depend on the async‑http‑client library, specifically any version earlier than 3.0.13 or 2.16.1. Applications using these legacy versions are vulnerable. The fix is available in 3.0.13 and 2.16.1 releases.

Risk and Exploitability

The reported CVSS score of 6.9 indicates a medium severity, with no EPSS data and the vulnerability not yet listed in KEV. The flaw can be exploited by local code that causes the library to process an adversarial HTTP response; once the cookie is cached, it is automatically appended to subsequent requests, potentially leading to confidentiality and integrity compromise. Because the attack requires building or modifying a Java application using AsyncHttpClient, it is typically a compromise of a deployment or supply‑chain rather than an external network attack. The attack vector is therefore "local code execution via a vulnerable library", and the risk is moderate to high for systems that process sensitive session data across domains.

Generated by OpenCVE AI on October 7, 2026 at 23:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade async-http-client to version 3.0.13 or 2.16.1 or later.
  • If an upgrade is delayed, configure the library to disable cookie sharing across multiple domains or manually validate cookie domain against a public suffix list before acceptance.
  • Verify that the application does not use the public cookie store in contexts where it could be abused; consider disabling cookie support for sensitive requests.

Generated by OpenCVE AI on October 7, 2026 at 23:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Description The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, ThreadSafeCookieStore validates Domain attributes with domain matching but does not reject public suffixes. A host beneath a suffix such as co.uk can set a cookie for that suffix, after which the shared cookie store sends it to unrelated hosts under the suffix. This can inject or overwrite session-relevant cookie values across origins. This issue is fixed in versions 3.0.13 and 2.16.1.
Title AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so a cookie can be set for co.uk
Weaknesses CWE-1275
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T21:15:13.870Z

Reserved: 2026-10-07T15:53:23.585Z

Link: CVE-2026-107280

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T22:17:03.810

Modified: 2026-10-07T22:17:03.810

Link: CVE-2026-107280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:15:08Z

Weaknesses
  • CWE-1275

    Sensitive Cookie with Improper SameSite Attribute