PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107229 AsyncHttpClient CVE debrief

The AsyncHttpClient library, used by Java applications for HTTP requests, had incomplete origin checks in its default cookie store from versions 2.16.0 to 3.0.13. This flaw allows for cookie tossing onto public-suffix and IP-address hosts, potentially leading to session fixation attacks when applications share a client across different trust domains.

Vendor
AsyncHttpClient
Product
async-http-client
CVSS
MEDIUM 4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders and developers using AsyncHttpClient in Java applications should assess exposure and prioritize remediation to prevent session fixation attacks. This includes verifying if applications use vulnerable versions of AsyncHttpClient and upgrading to version 3.0.14 or applying compensating controls. Security teams and vulnerability management teams should also review the vulnerability and its potential impact on their systems.

Why it matters

The AsyncHttpClient vulnerability allows for cookie tossing and session fixation attacks, impacting defenders and developers using vulnerable versions in Java applications.

  • Session fixation attacks possible when applications share a client across different trust domains
  • Potential for attackers to inject cookies and manipulate sessions
  • Need to verify if applications use vulnerable versions of AsyncHttpClient
  • Prioritize upgrading to AsyncHttpClient version 3.0.14 or applying compensating controls

Technical summary

The AsyncHttpClient library had incomplete origin checks in its default cookie store, allowing for cookie tossing onto public-suffix and IP-address hosts. This flaw, present in versions 2.16.0 to 3.0.13, can lead to session fixation attacks when applications share a client across different trust domains. The vulnerability arises from missing private-section and default public-suffix rules, absent A-label normalization, locale-sensitive lowercasing, public-suffix host-only handling, and numeric or IP host checks. These weaknesses enable an origin to store a cookie that can later be sent to another origin, potentially leading to session fixation attacks. Applications that share one client across trust domains can

Defensive priority

Defenders should prioritize verifying if their applications use vulnerable versions of AsyncHttpClient and upgrading to version 3.0.14 or applying compensating controls to mitigate the risk of session fixation attacks.

Recommended defensive actions

  • Verify if applications use vulnerable versions of AsyncHttpClient
  • Upgrade to AsyncHttpClient version 3.0.14 or later
  • Implement compensating controls to mitigate session fixation attacks
  • Monitor applications for suspicious cookie activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability in AsyncHttpClient versions from 2.16.0 to 3.0.13. Evidence is based on official CVE Program and NVD records, as well as GitHub advisories and code changes.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107229 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107229

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107229 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107229

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossing onto

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107229.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-qjr7-w8pj-pmv9

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.