The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie Domain attributes. Missing private-section and default public-suffix rules, absent A-label normalization, locale-sensitive lowercasing, public-suffix host-only handling, and numeric or IP host checks allow one origin to store a cookie later sent to another origin. Applications sharing one client across trust domains can therefore receive attacker-injected cookies and may be exposed to session fixation. This issue is fixed in version 3.0.14.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-1275",
"CWE-384"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107229.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107229.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"33087627559746334733055649192559444069",
"174284107661717695606729850883713530180",
"109145464982146699055316524616666545751",
"148339253466060478337098028124600990708"
],
"threshold": 0.9
},
"id": "CVE-2026-107229-0d88ebe5",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "276864848472423719414757550086002885130",
"length": 1560
},
"id": "CVE-2026-107229-17dc17fe",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/test/java/org/asynchttpclient/netty/handler/intercept/RedirectCookieRotationTest.java",
"function": "handle"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "106814611372285579444677840612955435961",
"length": 1863
},
"id": "CVE-2026-107229-28734980",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/test/java/org/asynchttpclient/netty/handler/intercept/RedirectCookieRotationTest.java",
"function": "configureHandler"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "115940402890807429955760986565602637476",
"length": 120
},
"id": "CVE-2026-107229-3b2325ff",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java",
"function": "domainsMatch"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"247694179419932114093793702843491239082",
"57211957134461112860058773182379275995",
"216080824044332933328412906970202310411",
"59405819059463446559593025959235047176",
"299312744527592712421706445106863422673",
"75894720239402336613015023292848159247",
"185015237781816424532507524630143645433",
"253708435705059957798605917225224170088",
"97115343038153427764245928886389711088",
"191539296830046224750723598236008461408",
"239775462559452874105975531493182810347",
"313720678631869063820877865354667288142",
"325688326483478929585940537661204293577",
"173943898435057278053090360309407341145",
"4709180722342919918902290985069289443",
"110747029792159351215596397069884192432",
"95159359966140867219714707020408453500",
"109533612602304150515050995468715208724",
"62656153810684508246929104297934449918",
"74120616183125299194991081336514149766",
"4052592507583876337734154454068745777",
"30631161873019928365998941926373366929",
"247210696621327228578754474573598524058",
"208439124980247623559633204981053315615",
"17362021996759348601791357669588383829",
"25720493374319289139560276406994158433",
"144597446968475953813647189542002899657",
"228253584051373068169897942583451754934",
"233235274460114274822121487217721683928"
],
"threshold": 0.9
},
"id": "CVE-2026-107229-3bd8224c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "265317588963511779018970140852205965214",
"length": 913
},
"id": "CVE-2026-107229-641ce594",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java",
"function": "add"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "330563532898594570748645521577256742314",
"length": 2332
},
"id": "CVE-2026-107229-6ec36339",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java",
"function": "exitAfterIntercept"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "312370062830392926848782787092014571970",
"length": 79
},
"id": "CVE-2026-107229-71714fc7",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java",
"function": "requestDomain"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "211172431976494218535757894318157688808",
"length": 333
},
"id": "CVE-2026-107229-74066133",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/main/java/org/asynchttpclient/uri/UriParser.java",
"function": "computeInitialScheme"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "6865819958901056120144211982719562395",
"length": 366
},
"id": "CVE-2026-107229-7fbc27f4",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java",
"function": "cookieDomain"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"194085218971423918351672527001465036859",
"141336872609680292515842545408262225761",
"236115854174370893464950668114956564614",
"11573342555884394794431823572959399438",
"242262271946618261313490570888123214600",
"48316514767524736772429414268698866344",
"287207809435390462090876377761222310749",
"4933259814561582187698866590100107738",
"48406188592455954159449924487562041820",
"298672238892429704270655493708135406415",
"144128759005398106200039476435346443390"
],
"threshold": 0.9
},
"id": "CVE-2026-107229-8d70fc1e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/test/java/org/asynchttpclient/netty/handler/intercept/RedirectCookieRotationTest.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"256976497602142119066324708626363925459",
"86741187361099052887177111067828616794",
"313914054448447323205948378595309688502",
"167957111778866701078860108538583502237",
"149361785834247464982042831524132464278",
"275622026211626529050788549752293225286",
"274105389113473717578584128717452691847",
"214210419419227967164426280539281432260",
"187726570627759142628813498970152384484",
"339437952405093852219468358342782624928",
"304324893235715318322205067908671500642"
],
"threshold": 0.9
},
"id": "CVE-2026-107229-951b0f84",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/test/java/org/asynchttpclient/cookie/PublicSuffixCookieTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "290711153745038152910324839129358776332",
"length": 396
},
"id": "CVE-2026-107229-ad56d4c3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java",
"function": "get"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "1023412899023067134538991106637957975",
"length": 462
},
"id": "CVE-2026-107229-bbf4b583",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/test/java/org/asynchttpclient/cookie/PublicSuffixCookieTest.java",
"function": "matchingDoesNotDependOnTheDefaultLocale"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"174135115827321605688648560259149190926",
"296632240457193039721626246023267517993",
"208473677295071005981444236329111900427",
"54472894365051758838080820115505025795",
"312910604288998101704086719912592704612",
"11234675333072737720347482587242135801",
"130846461444494649932487497157587135491",
"167955448420678513278123579041915286157",
"265982438466981375203183896434691899000",
"279379031461672288442368596249162255124",
"10928255603295237853162815325285886657",
"132225577470641782781375161952402436318",
"313158642643768397744730229846186811439",
"208947099844355703655791073678716881198",
"168467507294931930693340425927954450842",
"4897861155229930331298258652756611504",
"47913561250901428473763436035396304620",
"185584592581581086792200876018648799785",
"251674873430826288757035124759273503050",
"30483950268209270079395523844370814008",
"113119896697765934241192951918636651482",
"101384915292668625134629660356451778279",
"112413554918931264338179563940130289539",
"57089443874382053284579200274847746064",
"40984194156150570535910081713561760865",
"249115769572635418192576401341938543280",
"266653017854504597785695437514758024105",
"183568569644043229459495129598891836116",
"35902536387443472121516728201853258441",
"162056186937370362122811838035742898454",
"311049525285794685723264305745708170986",
"129349975429647033139101295661628000491",
"16654500804302709650693920544626835771",
"123532522852325830043277178959754771285"
],
"threshold": 0.9
},
"id": "CVE-2026-107229-cf43f84f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "298986444797709434117966201905479988645",
"length": 475
},
"id": "CVE-2026-107229-e85a4520",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/main/java/org/asynchttpclient/cookie/PublicSuffixList.java",
"function": "isPublicSuffix"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "216529552554099928734629029204801405992",
"length": 896
},
"id": "CVE-2026-107229-ee8f22f7",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java",
"function": "of"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"163460617041448915435106570125163341177",
"220693160014543210602000580773444817323",
"325972425223094014321290181614380074682",
"170990231085234808916357038511038412227",
"71761630122404921022274347410132561970",
"179691288432850565026342880730492233152",
"106768672560629387791532116331993506400",
"235026464766744766020642873036220476567",
"139892491487293749831709586418903057307",
"295062653115761824623142948979136043232",
"295387080296510626730213342130333809618",
"9293357313110225933203648058232993985",
"153309781410899137015980477577417120231",
"648867112131648685003376047807699052",
"167628217003687880709534423656366522074",
"264111976902312291337484820911767945997",
"291981110659552161648943657997973306610",
"333275199811182498877548502249392879602",
"300534355349738429695812239761351601032",
"291835942639428180096515659950965175178",
"71672733182417891482004804307179310506",
"117092101910584726925119959069510813894",
"44674223638796070971011854980683711845",
"253252397768399543515749821963214578802",
"45851374566771631151152579095951606809",
"233374085794502757110388840974997936507",
"18804661826057169267913436296366649171",
"149764423673691890771710714194679048040",
"282787580347465578637188518929430460969",
"204424926367979055994395256887273834446",
"218075727629212283065108900863705824394",
"15689139872896914115608196315679095318",
"177690024590699536347165037699011076547"
],
"threshold": 0.9
},
"id": "CVE-2026-107229-f0227e5f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/main/java/org/asynchttpclient/cookie/PublicSuffixList.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"303465232377018570292147095408148422132",
"68540916644121381074444004811484803651",
"42347147065416192873448999259098185416",
"275184213013584246598154864022780096429",
"16661186105824384935564268691375229986",
"84825862606863240363320174168073169201",
"243465948167404466498370112425698889302"
],
"threshold": 0.9
},
"id": "CVE-2026-107229-fa04ea08",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
"target": {
"file": "client/src/main/java/org/asynchttpclient/uri/UriParser.java"
}
}
]
"2026-10-09T07:06:48Z"