PT-2026-107678 · Unknown · Async Http Client

CVE-2026-107228

·

Published

2026-10-07

·

Updated

2026-10-08

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions AsyncHttpClient versions 2.1.0 through 3.0.13
Description The enabled-by-default cookie store in the AsyncHttpClient library replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client environment, stored cookies from one user may replace the request cookie of another user, leading to the request being executed under an incorrect session.
Recommendations Update to version 3.0.14.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107228
GHSA-2JWH-9RMR-J4XF

Affected Products

Async Http Client