CVE-2026-107229: AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossing onto public-suffix and IP-address hosts
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie Domain attributes. Missing private-section and default public-suffix rules, absent A-label normalization, locale-sensitive lowercasing, public-suffix host-only handling, and numeric or IP host checks allow one origin to store a cookie later sent to another origin. Applications sharing one client across trust domains can therefore receive attacker-injected cookies and may be exposed to session fixation. This issue is fixed in version 3.0.14.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AsyncHttpClientto a version that resolves this vulnerability.Fixed in 3.0.14
Event History
Frequently Asked Questions
Which versions need remediation?
Versions from 2.16.0 up to, but not including, 3.0.14 are affected. The issue is fixed in 3.0.14.
Which applications are most exposed?
Applications that share a single AsyncHttpClient instance across different trust domains are exposed to cross-origin cookie injection. This can lead to session fixation where injected cookies influence requests to another origin.
Does this affect use of the built-in cookie handling?
Yes. The affected component is the default ThreadSafeCookieStore, so applications using that store on affected releases may be vulnerable.
What does an attacker need to do?
An attacker needs to use one origin to set a cookie that the incomplete validation later permits to be sent to another origin. The vulnerability does not require attacker privileges or user interaction, but exploitation has high attack complexity.
What can be done before upgrading?
Avoid sharing an AsyncHttpClient instance across trust domains where possible. Separating clients by trust domain reduces the scenario in which an attacker-injected cookie can be carried between origins.