PatchSiren cyber security CVE debrief
CVE-2026-107228 AsyncHttpClient CVE debrief
The AsyncHttpClient library, used by Java applications for HTTP requests, had a vulnerability where its cookie store could silently override explicit Cookie headers set by callers, potentially causing requests to be executed under the wrong session. This issue, fixed in version 3.0.14, bypassed a previous fix for CVE-2024-53990 and could impact shared client scenarios.
- Vendor
- AsyncHttpClient
- Product
- async-http-client
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders managing Java applications that use AsyncHttpClient, especially in shared client environments, should assess their exposure and prioritize upgrading to version 3.0.14 or later.
Why it matters
Defenders should care about CVE-2026-107228 because it affects the AsyncHttpClient library used in Java applications, potentially allowing session hijacking and unauthorized actions in shared client environments. The vulnerability requires verification of the current AsyncHttpClient version and usage, with a priority on upgrading to version 3.0.14 or later to mitigate the issue.
- Session hijacking in shared client environments
- Potential for unauthorized actions under wrong user sessions
- Need for verification of current AsyncHttpClient version and usage
- Prioritization of upgrades to version 3.0.14 or later
Technical summary
The AsyncHttpClient library, used for HTTP requests in Java applications, had a vulnerability where its enabled-by-default cookie store would replace explicit Cookie headers set through setHeader or addHeader with stored cookies for the origin. This could lead to requests being executed under the wrong session in shared client scenarios, bypassing the fix for CVE-2024-53990. The issue is addressed in version 3.0.14.
Defensive priority
Defenders should prioritize verifying and upgrading to version 3.0.14 or later, especially in shared client environments, and review their current usage of AsyncHttpClient for potential exposure.
Recommended defensive actions
- Verify and upgrade AsyncHttpClient to version 3.0.14 or later
- Review usage of AsyncHttpClient in shared client environments for potential exposure
- Monitor for any unusual session activity that could indicate exploitation
- Perform a thorough review of current AsyncHttpClient configurations and usage
- Implement additional monitoring for session activity in shared client environments
- Conduct an asset inventory to identify all systems using AsyncHttpClient
- Track exceptions and retest remediated assets to ensure vulnerability resolution
Evidence notes
The CVE record and source item provide details on the vulnerability, its impact, and the fix in version 3.0.14. However, specific instances of exploitation or affected applications beyond the AsyncHttpClient library itself are not detailed.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107228 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107228
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107228 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107228
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHeader (By
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107228.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-2jwh-9rmr-j4xf
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.