CVE-2026-107226: CSRF

Published Oct 8, 2026
·
Updated

Impact The cookie store ignores the scheme a Set-Cookie arrived on. draft-ietf-httpbis-rfc6265bis-22 (approved to obsolete RFC 6265, in the RFC Editor queue) Section 5.7 requires a user agent to ignore a cookie with the Secure attribute unless it arrived over a secure connection (step 13), and to ignore a non-Secure cookie from an insecure connection when it would overlay a Secure cookie the store already holds (step 16). Neither rule is implemented. The only Secure handling is on retrieval, where a Secure cookie is not sent over plaintext.

So anyone who can answer a plaintext request to a site can set, replace or delete the site's Secure cookies, and the next HTTPS request carries the attacker's value back inside TLS:

http://example.com -> Set-Cookie: SID=attacker-value; Secure; Path=/ https://example.com -> Cookie: SID=attacker-value

This does not need an attacker on the network path. A plaintext host under the same site reaches the HTTPS one by setting a domain cookie:

http://insecure.example.com -> Set-Cookie: SID=attacker-value; Secure; Domain=example.com; Path=/ https://bank.example.com -> Cookie: SID=attacker-value

A plaintext Set-Cookie of the same name, domain and path overwrites a Secure cookie, and one with Max-Age=0 deletes it. Depending on what the application does with the cookie, this is session fixation into the HTTPS session, an overwritten CSRF token, or the removal of a cookie the site relies on. Unlike GHSA-qjr7-w8pj-pmv9, which can only add a cookie, this replaces or deletes one, hence Integrity: High; the harm lands on the HTTPS site, hence Scope: Changed.

Affected versions 3.x: up to and including 3.0.13 2.x: from 2.1.0, when the cookie store was introduced, up to and including 2.16.1

Patches Fixed in 3.0.14 on the 3.x line. A cookie with the Secure attribute is ignored unless the request was secure, and a non-Secure cookie from a request that did not use TLS is ignored when it would overlay a Secure cookie of the same name whose path its own path falls under. A plaintext response can therefore no longer plant, overwrite or delete a Secure cookie.

When several cookies of one name match a request, the client sends only the first, so the order in which the store returns them decides which one is used. That order is now: on a secure request, cookies received in a secure context (HTTPS, WSS or plaintext loopback) first; then the request host's own cookies before cookies set for a parent domain; then, within one host, longer paths first. A plaintext attacker cannot outrank a cookie the site set over HTTPS by ordering or padding its own cookies, or by setting one before the site sets its own.

Plaintext requests to localhost, or to an address literal that is a loopback address, count as secure, so a development server that sets Secure cookies over http://localhost gets them back. This is limited to the cookies such a server set itself: a Secure cookie that arrived over HTTPS is never sent over plaintext, loopback included, and a plaintext loopback port cannot overlay it. Numeric spellings that are not address literals, such as 127.0.0.256, and names under localhost are not treated as loopback, because the client resolves them as names.

The 2.x line is end of life and will not receive a fix. Upgrade to 3.0.14.

Workarounds Do not share one CookieStore between plaintext and HTTPS origins that are not mutually trusted, including hosts under the same site. Disabling the cookie store also avoids it.

Details ThreadSafeCookieStore.add(Uri, Cookie) reduces the request to its host and path before storing, so the scheme never reaches the code that decides whether to keep a cookie. get(Uri) does read it, but only to leave Secure cookies out of plaintext requests.

A narrower form survives the two storage rules on their own. The step 16 path test is one-way by design, so a plaintext SID for Path=/ is legitimately stored beside a Secure SID for Path=/account, and both match a request under /account. The store returned matching cookies in hash order, and the client keeps only the first cookie of each name when it builds the request (RequestBuilderBase.addCookieIfUnset), so an attacker could decide which one was sent, for example by padding one plaintext response with filler cookies. The ordering described above closes it.

The fix does not stop an HTTPS host under the same site from setting a domain cookie for a name the request host never sets itself. Only a Host- cookie name prefix prevents that, and the client does not enforce cookie name prefixes.

Attribution

AI-assisted tools were used to support discovery and analysis.

Affected Software

2 affected componentsFixes available
maven/org.asynchttpclient:async-http-client>=2.1.0<=2.16.1
maven/org.asynchttpclient:async-http-client>=3.0.0<=3.0.13
3.0.14

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.asynchttpclient:async-http-client to a version that resolves this vulnerability.

    Fixed in 3.0.14
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 3.0.14
  3. Configuration

    Disable the cookie store to avoid the vulnerability.

    CookieStore cookie store = disabled
  4. Compensating control

    Do not share one CookieStore between plaintext and HTTPS origins that are not mutually trusted, including hosts under the same site.

Event History

Oct 8, 2026
Advisory Published
via GitHub·04:49 PM
Data Sourced
via GitHub·04:49 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments are exposed when the client uses a shared cookie store and makes plaintext HTTP requests to a site that also uses HTTPS cookies. A plaintext sibling host under the same site can also affect an HTTPS host by setting a domain cookie.

2

What does an attacker need to exploit it?

An attacker needs to be able to answer a plaintext HTTP request for the target site or a related plaintext host. They do not need to be on the network path, and no authentication or user interaction is required.

3

What can be done while an update is not immediately available?

Avoid making plaintext HTTP requests to hosts that share cookies with HTTPS services, including insecure sibling subdomains. This prevents those responses from setting, replacing, or deleting cookies used by the HTTPS service.

4

Is there a release associated with a fix?

The provided references include the async-http-client-project-3.0.14 release and the associated fix commit. Verify the release notes and your dependency version when planning remediation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203