The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-287"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107228.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107228.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "313603061959576688548777385639564162930",
"length": 4032
},
"id": "CVE-2026-107228-02faa2b6",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java",
"function": "exitAfterHandlingRedirect"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"287069903123008852882841889913397143074",
"191838875415762874642176763336217022120",
"113797460107587920888555199139928196212",
"103804818187391539090885865114205550594",
"182346267471002759321306061961817230341",
"144714281036865929407480854553598484279",
"288814041628016585885127686075437221844",
"213390825785352973793750739874174814404",
"70788294503808365467827103474380359682",
"275145303984969573359390435236421562021",
"314062207477349738109207967216326617891",
"242552941518224108318336312870509912610"
],
"threshold": 0.9
},
"id": "CVE-2026-107228-3b2e8a97",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"131813821150373505620774268007306264503",
"193621198389632918908923865843040210504",
"208320048997645960997154809074017260448",
"34308804407403879095937292396502725315",
"237189984971397957599218815152331293078",
"160044918139477595106355276220402077707",
"60047714855156046610284336938024895363",
"52998305829158081851656410722162708070",
"63362322890425750796743428220565539738",
"201765198644889074114671127464533685051",
"64880555049755556472985015206633017435",
"24736618307450635658946862674823019712",
"88111044465016833162555050742681178962",
"52771326476915651147735692907963057765",
"83349843552220294363276974189387685097",
"237845449785090346776314012687950506052",
"96349964609859721993763064892438406574",
"295888715283424355124800102279176408284",
"199521661099934714503105398657266481865",
"132157563206171442787170228041694564597"
],
"threshold": 0.9
},
"id": "CVE-2026-107228-7cc4e1b4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestFactory.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"239690584058812298211859179517373029985",
"16044321736028551889640708483344368397",
"199914722048295196205805804439511726906"
],
"threshold": 0.9
},
"id": "CVE-2026-107228-a01aca0a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
"target": {
"file": "client/src/test/java/org/asynchttpclient/netty/handler/intercept/RedirectCookieRotationTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "18351566744866301822787804471387203771",
"length": 603
},
"id": "CVE-2026-107228-a1635f8a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java",
"function": "propagatedHeaders"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"153227647759387577818628900119438660106",
"41572496521538229573533027958985371551",
"307299973282187188779667715712473709632",
"243508187588480454342307296868628008686",
"250529020770641903196583267582094170694",
"192587502608494044156846631721658155088",
"127951931999617742542890735157417724090",
"247694179419932114093793702843491239082",
"149344885802355013855684752970707055196",
"212900781779656746574786280417023274013",
"212408094802880442371339501342517618011",
"1030524342785002509039580950146360854",
"100892034106718292396103506302439123028",
"177363156482294000041482317455850921267",
"37020120704538961883271891393705791545",
"269691904290460280372371368876051462203",
"207398947181489958571551128607706751317",
"312149197585668114129080980000884922687",
"104119789342903949346560542298742739645",
"193343541369458030859272478299878306108",
"138375113865737918058242639310936678376",
"262836725046648004713320628983202047971",
"126662453710966849278202533947481184509",
"119756437360289680115624826811648085903",
"259139591301458106063580406993904455456"
],
"threshold": 0.9
},
"id": "CVE-2026-107228-d1b91c76",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "327884523773490273323951324865420312209",
"length": 278
},
"id": "CVE-2026-107228-da00feba",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java",
"function": "refresh"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"286446077946549461972192985029569759549",
"203229685696938595454879280339250205871",
"155550159802052143491768614918434571899"
],
"threshold": 0.9
},
"id": "CVE-2026-107228-de42cf23",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
"target": {
"file": "client/src/test/java/org/asynchttpclient/netty/handler/intercept/AuthRetryCookieTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "9500407417655056984423392268729190784",
"length": 1049
},
"id": "CVE-2026-107228-f0ed2c83",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java",
"function": "of"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "76738329251562025766797757408856436878",
"length": 3774
},
"id": "CVE-2026-107228-fee08627",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestFactory.java",
"function": "newNettyRequest"
}
}
]
"2026-10-09T07:06:49Z"