PatchSiren cyber security CVE debrief
CVE-2026-107280 AsyncHttpClient CVE debrief
The AsyncHttpClient library for Java, prior to versions 3.0.13 and 2.16.1, contains a vulnerability where the Domain attribute of cookies is not checked against the public suffix list. This allows a host beneath a public suffix, such as co.uk, to set a cookie for that suffix. Consequently, the shared cookie store sends this cookie to unrelated hosts under the same suffix, potentially leading to the injection or overwrite of session-relevant cookie values across different origins.
- Vendor
- AsyncHttpClient
- Product
- async-http-client
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Java applications using AsyncHttpClient, especially those handling sensitive session data, should assess exposure and prioritize remediation. This includes verifying application versions and updating to fixed versions or implementing compensating controls.
Why it matters
The vulnerability in AsyncHttpClient allows improper setting of cookies across origins, potentially leading to session hijacking and unauthorized access. Defenders should assess exposure, prioritize remediation, and implement compensating controls. Evidence is limited to CVE and source item details.
- Session hijacking through cookie manipulation
- Potential for unauthorized access to sensitive data
- Need for enhanced monitoring of cookie-related activities
- Verification of application versions and remediation prioritization
Technical summary
The AsyncHttpClient library for Java does not properly validate the Domain attribute of cookies against the public suffix list. This flaw allows a host beneath a public suffix (e.g., co.uk) to set a cookie for that suffix. The shared cookie store then sends this cookie to unrelated hosts under the same suffix, potentially leading to session-relevant cookie value injection or overwrite across origins.
Defensive priority
Defenders should prioritize assessing exposure in Java applications utilizing AsyncHttpClient, especially those handling sensitive session data, and verify if they are using vulnerable versions (3.0.0 to 3.0.12 or 2.0.0 to 2.16.0). Immediate remediation includes updating to versions 3.0.13 or 2.16.1, and implementing compensating controls such as enhanced session management and cookie security measures.
Recommended defensive actions
- Assess exposure in Java applications using AsyncHttpClient, focusing on those handling sensitive session data.
- Verify if applications are using vulnerable versions (3.0.0 to 3.0.12 or 2.0.0 to 2.16.0).
- Update to versions 3.0.13 or 2.16.1.
- Implement enhanced session management and cookie security measures as compensating controls.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and source item provide details on the vulnerability in AsyncHttpClient. The issue is fixed in versions 3.0.13 and 2.16.1. However, specific details about exploitation, victims, or business impact are not provided, limiting the depth of the analysis.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107280 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107280
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107280 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107280
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so a coo
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107280.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f9m8-cv68-674w
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/commit/330267895fe0bdb41bbd027ea6b151d38ee7c23d
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.