CVE-2026-107228: Asynchttpclient Async-HTTP-Client
Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14.
Affected products
- Asynchttpclient Async-HTTP-Client: from 3.0.0, before 3.0.14 (fixed in 3.0.14); from 2.1.0, up to and including 2.16.1
Published 2026-10-07. Last modified 2026-10-08.