CVE-2026-107229: AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossing onto public-suffix and IP-address hosts

Published Oct 7, 2026
·
Updated

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie Domain attributes. Missing private-section and default public-suffix rules, absent A-label normalization, locale-sensitive lowercasing, public-suffix host-only handling, and numeric or IP host checks allow one origin to store a cookie later sent to another origin. Applications sharing one client across trust domains can therefore receive attacker-injected cookies and may be exposed to session fixation. This issue is fixed in version 3.0.14.

Affected Software

1 affected component
AsyncHttpClient AsyncHttpClient>=2.16.0<3.0.14

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade AsyncHttpClient to a version that resolves this vulnerability.

    Fixed in 3.0.14

Event History

Oct 7, 2026
CVE Published
via MITRE·08:57 PM
Data Sourced
via MITRE·08:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which versions need remediation?

Versions from 2.16.0 up to, but not including, 3.0.14 are affected. The issue is fixed in 3.0.14.

2

Which applications are most exposed?

Applications that share a single AsyncHttpClient instance across different trust domains are exposed to cross-origin cookie injection. This can lead to session fixation where injected cookies influence requests to another origin.

3

Does this affect use of the built-in cookie handling?

Yes. The affected component is the default ThreadSafeCookieStore, so applications using that store on affected releases may be vulnerable.

4

What does an attacker need to do?

An attacker needs to use one origin to set a cookie that the incomplete validation later permits to be sent to another origin. The vulnerability does not require attacker privileges or user interaction, but exploitation has high attack complexity.

5

What can be done before upgrading?

Avoid sharing an AsyncHttpClient instance across trust domains where possible. Separating clients by trust domain reduces the scenario in which an attacker-injected cookie can be carried between origins.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203