CVE-2026-107229

Source
https://cve.org/CVERecord?id=CVE-2026-107229
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107229.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107229
Aliases
  • GHSA-qjr7-w8pj-pmv9
Downstream
Published
2026-10-07T20:57:36Z
Modified
2026-10-09T07:06:48Z
Severity
  • 4.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N CVSS Calculator
Summary
AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossing onto public-suffix and IP-address hosts
Details

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie Domain attributes. Missing private-section and default public-suffix rules, absent A-label normalization, locale-sensitive lowercasing, public-suffix host-only handling, and numeric or IP host checks allow one origin to store a cookie later sent to another origin. Applications sharing one client across trust domains can therefore receive attacker-injected cookies and may be exposed to session fixation. This issue is fixed in version 3.0.14.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-1275",
        "CWE-384"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107229.json"
}
References

Affected packages

Git / github.com/asynchttpclient/async-http-client

Affected ranges

Type
GIT
Repo
https://github.com/asynchttpclient/async-http-client
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.0.11"
        },
        {
            "fixed": "3.0.14"
        },
        {
            "introduced": "2.16.0"
        },
        {
            "last_affected": "2.16.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

async-http-client-project-3.*
async-http-client-project-3.0.11
async-http-client-project-3.0.12
async-http-client-project-3.0.13

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107229.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "33087627559746334733055649192559444069",
                "174284107661717695606729850883713530180",
                "109145464982146699055316524616666545751",
                "148339253466060478337098028124600990708"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107229-0d88ebe5",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "276864848472423719414757550086002885130",
            "length": 1560
        },
        "id": "CVE-2026-107229-17dc17fe",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/test/java/org/asynchttpclient/netty/handler/intercept/RedirectCookieRotationTest.java",
            "function": "handle"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "106814611372285579444677840612955435961",
            "length": 1863
        },
        "id": "CVE-2026-107229-28734980",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/test/java/org/asynchttpclient/netty/handler/intercept/RedirectCookieRotationTest.java",
            "function": "configureHandler"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "115940402890807429955760986565602637476",
            "length": 120
        },
        "id": "CVE-2026-107229-3b2325ff",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java",
            "function": "domainsMatch"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "247694179419932114093793702843491239082",
                "57211957134461112860058773182379275995",
                "216080824044332933328412906970202310411",
                "59405819059463446559593025959235047176",
                "299312744527592712421706445106863422673",
                "75894720239402336613015023292848159247",
                "185015237781816424532507524630143645433",
                "253708435705059957798605917225224170088",
                "97115343038153427764245928886389711088",
                "191539296830046224750723598236008461408",
                "239775462559452874105975531493182810347",
                "313720678631869063820877865354667288142",
                "325688326483478929585940537661204293577",
                "173943898435057278053090360309407341145",
                "4709180722342919918902290985069289443",
                "110747029792159351215596397069884192432",
                "95159359966140867219714707020408453500",
                "109533612602304150515050995468715208724",
                "62656153810684508246929104297934449918",
                "74120616183125299194991081336514149766",
                "4052592507583876337734154454068745777",
                "30631161873019928365998941926373366929",
                "247210696621327228578754474573598524058",
                "208439124980247623559633204981053315615",
                "17362021996759348601791357669588383829",
                "25720493374319289139560276406994158433",
                "144597446968475953813647189542002899657",
                "228253584051373068169897942583451754934",
                "233235274460114274822121487217721683928"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107229-3bd8224c",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "265317588963511779018970140852205965214",
            "length": 913
        },
        "id": "CVE-2026-107229-641ce594",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java",
            "function": "add"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "330563532898594570748645521577256742314",
            "length": 2332
        },
        "id": "CVE-2026-107229-6ec36339",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java",
            "function": "exitAfterIntercept"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "312370062830392926848782787092014571970",
            "length": 79
        },
        "id": "CVE-2026-107229-71714fc7",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java",
            "function": "requestDomain"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "211172431976494218535757894318157688808",
            "length": 333
        },
        "id": "CVE-2026-107229-74066133",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/uri/UriParser.java",
            "function": "computeInitialScheme"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "6865819958901056120144211982719562395",
            "length": 366
        },
        "id": "CVE-2026-107229-7fbc27f4",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java",
            "function": "cookieDomain"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "194085218971423918351672527001465036859",
                "141336872609680292515842545408262225761",
                "236115854174370893464950668114956564614",
                "11573342555884394794431823572959399438",
                "242262271946618261313490570888123214600",
                "48316514767524736772429414268698866344",
                "287207809435390462090876377761222310749",
                "4933259814561582187698866590100107738",
                "48406188592455954159449924487562041820",
                "298672238892429704270655493708135406415",
                "144128759005398106200039476435346443390"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107229-8d70fc1e",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/test/java/org/asynchttpclient/netty/handler/intercept/RedirectCookieRotationTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "256976497602142119066324708626363925459",
                "86741187361099052887177111067828616794",
                "313914054448447323205948378595309688502",
                "167957111778866701078860108538583502237",
                "149361785834247464982042831524132464278",
                "275622026211626529050788549752293225286",
                "274105389113473717578584128717452691847",
                "214210419419227967164426280539281432260",
                "187726570627759142628813498970152384484",
                "339437952405093852219468358342782624928",
                "304324893235715318322205067908671500642"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107229-951b0f84",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/test/java/org/asynchttpclient/cookie/PublicSuffixCookieTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "290711153745038152910324839129358776332",
            "length": 396
        },
        "id": "CVE-2026-107229-ad56d4c3",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java",
            "function": "get"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "1023412899023067134538991106637957975",
            "length": 462
        },
        "id": "CVE-2026-107229-bbf4b583",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/test/java/org/asynchttpclient/cookie/PublicSuffixCookieTest.java",
            "function": "matchingDoesNotDependOnTheDefaultLocale"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "174135115827321605688648560259149190926",
                "296632240457193039721626246023267517993",
                "208473677295071005981444236329111900427",
                "54472894365051758838080820115505025795",
                "312910604288998101704086719912592704612",
                "11234675333072737720347482587242135801",
                "130846461444494649932487497157587135491",
                "167955448420678513278123579041915286157",
                "265982438466981375203183896434691899000",
                "279379031461672288442368596249162255124",
                "10928255603295237853162815325285886657",
                "132225577470641782781375161952402436318",
                "313158642643768397744730229846186811439",
                "208947099844355703655791073678716881198",
                "168467507294931930693340425927954450842",
                "4897861155229930331298258652756611504",
                "47913561250901428473763436035396304620",
                "185584592581581086792200876018648799785",
                "251674873430826288757035124759273503050",
                "30483950268209270079395523844370814008",
                "113119896697765934241192951918636651482",
                "101384915292668625134629660356451778279",
                "112413554918931264338179563940130289539",
                "57089443874382053284579200274847746064",
                "40984194156150570535910081713561760865",
                "249115769572635418192576401341938543280",
                "266653017854504597785695437514758024105",
                "183568569644043229459495129598891836116",
                "35902536387443472121516728201853258441",
                "162056186937370362122811838035742898454",
                "311049525285794685723264305745708170986",
                "129349975429647033139101295661628000491",
                "16654500804302709650693920544626835771",
                "123532522852325830043277178959754771285"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107229-cf43f84f",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "298986444797709434117966201905479988645",
            "length": 475
        },
        "id": "CVE-2026-107229-e85a4520",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/cookie/PublicSuffixList.java",
            "function": "isPublicSuffix"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "216529552554099928734629029204801405992",
            "length": 896
        },
        "id": "CVE-2026-107229-ee8f22f7",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java",
            "function": "of"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "163460617041448915435106570125163341177",
                "220693160014543210602000580773444817323",
                "325972425223094014321290181614380074682",
                "170990231085234808916357038511038412227",
                "71761630122404921022274347410132561970",
                "179691288432850565026342880730492233152",
                "106768672560629387791532116331993506400",
                "235026464766744766020642873036220476567",
                "139892491487293749831709586418903057307",
                "295062653115761824623142948979136043232",
                "295387080296510626730213342130333809618",
                "9293357313110225933203648058232993985",
                "153309781410899137015980477577417120231",
                "648867112131648685003376047807699052",
                "167628217003687880709534423656366522074",
                "264111976902312291337484820911767945997",
                "291981110659552161648943657997973306610",
                "333275199811182498877548502249392879602",
                "300534355349738429695812239761351601032",
                "291835942639428180096515659950965175178",
                "71672733182417891482004804307179310506",
                "117092101910584726925119959069510813894",
                "44674223638796070971011854980683711845",
                "253252397768399543515749821963214578802",
                "45851374566771631151152579095951606809",
                "233374085794502757110388840974997936507",
                "18804661826057169267913436296366649171",
                "149764423673691890771710714194679048040",
                "282787580347465578637188518929430460969",
                "204424926367979055994395256887273834446",
                "218075727629212283065108900863705824394",
                "15689139872896914115608196315679095318",
                "177690024590699536347165037699011076547"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107229-f0227e5f",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/cookie/PublicSuffixList.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "303465232377018570292147095408148422132",
                "68540916644121381074444004811484803651",
                "42347147065416192873448999259098185416",
                "275184213013584246598154864022780096429",
                "16661186105824384935564268691375229986",
                "84825862606863240363320174168073169201",
                "243465948167404466498370112425698889302"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107229-fa04ea08",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9",
        "target": {
            "file": "client/src/main/java/org/asynchttpclient/uri/UriParser.java"
        }
    }
]
vanir_signatures_modified
"2026-10-09T07:06:48Z"