PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107280 AsyncHttpClient CVE debrief

The AsyncHttpClient library for Java, prior to versions 3.0.13 and 2.16.1, contains a vulnerability where the Domain attribute of cookies is not checked against the public suffix list. This allows a host beneath a public suffix, such as co.uk, to set a cookie for that suffix. Consequently, the shared cookie store sends this cookie to unrelated hosts under the same suffix, potentially leading to the injection or overwrite of session-relevant cookie values across different origins.

Vendor
AsyncHttpClient
Product
async-http-client
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Java applications using AsyncHttpClient, especially those handling sensitive session data, should assess exposure and prioritize remediation. This includes verifying application versions and updating to fixed versions or implementing compensating controls.

Why it matters

The vulnerability in AsyncHttpClient allows improper setting of cookies across origins, potentially leading to session hijacking and unauthorized access. Defenders should assess exposure, prioritize remediation, and implement compensating controls. Evidence is limited to CVE and source item details.

  • Session hijacking through cookie manipulation
  • Potential for unauthorized access to sensitive data
  • Need for enhanced monitoring of cookie-related activities
  • Verification of application versions and remediation prioritization

Technical summary

The AsyncHttpClient library for Java does not properly validate the Domain attribute of cookies against the public suffix list. This flaw allows a host beneath a public suffix (e.g., co.uk) to set a cookie for that suffix. The shared cookie store then sends this cookie to unrelated hosts under the same suffix, potentially leading to session-relevant cookie value injection or overwrite across origins.

Defensive priority

Defenders should prioritize assessing exposure in Java applications utilizing AsyncHttpClient, especially those handling sensitive session data, and verify if they are using vulnerable versions (3.0.0 to 3.0.12 or 2.0.0 to 2.16.0). Immediate remediation includes updating to versions 3.0.13 or 2.16.1, and implementing compensating controls such as enhanced session management and cookie security measures.

Recommended defensive actions

  • Assess exposure in Java applications using AsyncHttpClient, focusing on those handling sensitive session data.
  • Verify if applications are using vulnerable versions (3.0.0 to 3.0.12 or 2.0.0 to 2.16.0).
  • Update to versions 3.0.13 or 2.16.1.
  • Implement enhanced session management and cookie security measures as compensating controls.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and source item provide details on the vulnerability in AsyncHttpClient. The issue is fixed in versions 3.0.13 and 2.16.1. However, specific details about exploitation, victims, or business impact are not provided, limiting the depth of the analysis.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107280 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107280

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107280 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107280

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so a coo

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107280.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f9m8-cv68-674w

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/330267895fe0bdb41bbd027ea6b151d38ee7c23d

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.