PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107228 AsyncHttpClient CVE debrief

The AsyncHttpClient library, used by Java applications for HTTP requests, had a vulnerability where its cookie store could silently override explicit Cookie headers set by callers, potentially causing requests to be executed under the wrong session. This issue, fixed in version 3.0.14, bypassed a previous fix for CVE-2024-53990 and could impact shared client scenarios.

Vendor
AsyncHttpClient
Product
async-http-client
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders managing Java applications that use AsyncHttpClient, especially in shared client environments, should assess their exposure and prioritize upgrading to version 3.0.14 or later.

Why it matters

Defenders should care about CVE-2026-107228 because it affects the AsyncHttpClient library used in Java applications, potentially allowing session hijacking and unauthorized actions in shared client environments. The vulnerability requires verification of the current AsyncHttpClient version and usage, with a priority on upgrading to version 3.0.14 or later to mitigate the issue.

  • Session hijacking in shared client environments
  • Potential for unauthorized actions under wrong user sessions
  • Need for verification of current AsyncHttpClient version and usage
  • Prioritization of upgrades to version 3.0.14 or later

Technical summary

The AsyncHttpClient library, used for HTTP requests in Java applications, had a vulnerability where its enabled-by-default cookie store would replace explicit Cookie headers set through setHeader or addHeader with stored cookies for the origin. This could lead to requests being executed under the wrong session in shared client scenarios, bypassing the fix for CVE-2024-53990. The issue is addressed in version 3.0.14.

Defensive priority

Defenders should prioritize verifying and upgrading to version 3.0.14 or later, especially in shared client environments, and review their current usage of AsyncHttpClient for potential exposure.

Recommended defensive actions

  • Verify and upgrade AsyncHttpClient to version 3.0.14 or later
  • Review usage of AsyncHttpClient in shared client environments for potential exposure
  • Monitor for any unusual session activity that could indicate exploitation
  • Perform a thorough review of current AsyncHttpClient configurations and usage
  • Implement additional monitoring for session activity in shared client environments
  • Conduct an asset inventory to identify all systems using AsyncHttpClient
  • Track exceptions and retest remediated assets to ensure vulnerability resolution

Evidence notes

The CVE record and source item provide details on the vulnerability, its impact, and the fix in version 3.0.14. However, specific instances of exploitation or affected applications beyond the AsyncHttpClient library itself are not detailed.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107228 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107228

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107228 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107228

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHeader (By

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107228.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-2jwh-9rmr-j4xf

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.