CVE-2026-107228

Source
https://cve.org/CVERecord?id=CVE-2026-107228
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107228.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107228
Aliases
Downstream
Published
2026-10-07T20:54:34Z
Modified
2026-10-09T07:06:49Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHeader (Bypass of CVE-2024-53990 Fix)
Details

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-287"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107228.json"
}
References

Affected packages

Git / github.com/asynchttpclient/async-http-client

Affected ranges

Type
GIT
Repo
https://github.com/asynchttpclient/async-http-client
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.0.14"
        },
        {
            "introduced": "2.1.0"
        },
        {
            "last_affected": "2.16.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

async-http-client-project-3.*
async-http-client-project-3.0.0
async-http-client-project-3.0.1
async-http-client-project-3.0.10
async-http-client-project-3.0.11
async-http-client-project-3.0.12
async-http-client-project-3.0.13
async-http-client-project-3.0.2
async-http-client-project-3.0.3
async-http-client-project-3.0.4
async-http-client-project-3.0.5
async-http-client-project-3.0.6
async-http-client-project-3.0.7
async-http-client-project-3.0.8
async-http-client-project-3.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107228.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "313603061959576688548777385639564162930",
            "length": 4032
        },
        "id": "CVE-2026-107228-02faa2b6",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java",
            "function": "exitAfterHandlingRedirect"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "287069903123008852882841889913397143074",
                "191838875415762874642176763336217022120",
                "113797460107587920888555199139928196212",
                "103804818187391539090885865114205550594",
                "182346267471002759321306061961817230341",
                "144714281036865929407480854553598484279",
                "288814041628016585885127686075437221844",
                "213390825785352973793750739874174814404",
                "70788294503808365467827103474380359682",
                "275145303984969573359390435236421562021",
                "314062207477349738109207967216326617891",
                "242552941518224108318336312870509912610"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107228-3b2e8a97",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "131813821150373505620774268007306264503",
                "193621198389632918908923865843040210504",
                "208320048997645960997154809074017260448",
                "34308804407403879095937292396502725315",
                "237189984971397957599218815152331293078",
                "160044918139477595106355276220402077707",
                "60047714855156046610284336938024895363",
                "52998305829158081851656410722162708070",
                "63362322890425750796743428220565539738",
                "201765198644889074114671127464533685051",
                "64880555049755556472985015206633017435",
                "24736618307450635658946862674823019712",
                "88111044465016833162555050742681178962",
                "52771326476915651147735692907963057765",
                "83349843552220294363276974189387685097",
                "237845449785090346776314012687950506052",
                "96349964609859721993763064892438406574",
                "295888715283424355124800102279176408284",
                "199521661099934714503105398657266481865",
                "132157563206171442787170228041694564597"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107228-7cc4e1b4",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestFactory.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "239690584058812298211859179517373029985",
                "16044321736028551889640708483344368397",
                "199914722048295196205805804439511726906"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107228-a01aca0a",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
        "target": {
            "file": "client/src/test/java/org/asynchttpclient/netty/handler/intercept/RedirectCookieRotationTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "18351566744866301822787804471387203771",
            "length": 603
        },
        "id": "CVE-2026-107228-a1635f8a",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java",
            "function": "propagatedHeaders"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "153227647759387577818628900119438660106",
                "41572496521538229573533027958985371551",
                "307299973282187188779667715712473709632",
                "243508187588480454342307296868628008686",
                "250529020770641903196583267582094170694",
                "192587502608494044156846631721658155088",
                "127951931999617742542890735157417724090",
                "247694179419932114093793702843491239082",
                "149344885802355013855684752970707055196",
                "212900781779656746574786280417023274013",
                "212408094802880442371339501342517618011",
                "1030524342785002509039580950146360854",
                "100892034106718292396103506302439123028",
                "177363156482294000041482317455850921267",
                "37020120704538961883271891393705791545",
                "269691904290460280372371368876051462203",
                "207398947181489958571551128607706751317",
                "312149197585668114129080980000884922687",
                "104119789342903949346560542298742739645",
                "193343541369458030859272478299878306108",
                "138375113865737918058242639310936678376",
                "262836725046648004713320628983202047971",
                "126662453710966849278202533947481184509",
                "119756437360289680115624826811648085903",
                "259139591301458106063580406993904455456"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107228-d1b91c76",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "327884523773490273323951324865420312209",
            "length": 278
        },
        "id": "CVE-2026-107228-da00feba",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java",
            "function": "refresh"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "286446077946549461972192985029569759549",
                "203229685696938595454879280339250205871",
                "155550159802052143491768614918434571899"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107228-de42cf23",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
        "target": {
            "file": "client/src/test/java/org/asynchttpclient/netty/handler/intercept/AuthRetryCookieTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "9500407417655056984423392268729190784",
            "length": 1049
        },
        "id": "CVE-2026-107228-f0ed2c83",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java",
            "function": "of"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "76738329251562025766797757408856436878",
            "length": 3774
        },
        "id": "CVE-2026-107228-fee08627",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/request/NettyRequestFactory.java",
            "function": "newNettyRequest"
        }
    }
]
vanir_signatures_modified
"2026-10-09T07:06:49Z"