CVE-2026-107229

Published: Ott 07, 2026 Last Modified: Ott 07, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 4,0
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: none
Integrity: low
Availability: none

Description

AI Translation Available

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie Domain attributes. Missing private-section and default public-suffix rules, absent A-label normalization, locale-sensitive lowercasing, public-suffix host-only handling, and numeric or IP host checks allow one origin to store a cookie later sent to another origin. Applications sharing one client across trust domains can therefore receive attacker-injected cookies and may be exposed to session fixation. This issue is fixed in version 3.0.14.

384

Session Fixation

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
Technologies: Web Based, Web Server
View CWE Details
1275

Sensitive Cookie with Improper SameSite Attribute

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Integrity Non-Repudiation Access Control
Potential Impacts:
Modify Application Data
Applicable Platforms
Technologies: Web Based, Web Server
View CWE Details
https://github.com/AsyncHttpClient/async-http-client/commit/7dc5bbc2d0a48aa2a9c…
https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-cl…
https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-q…