The CVE-2026-55688 vulnerability affects the AsyncHttpClient library, used for asynchronous HTTP requests in Java applications. This library improperly handles the Domain attribute when storing cookies, leading to a cookie injection issue. Versions 2.0.0 to 2.15.0 and 3.0.0.Beta1 to 3.0.10 are impacted. An attacker can exploit this by setting a cookie for an unrelated domain, which the client will then se [truncated]
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin, the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` an [truncated]