GHSA-f9m8-cv68-674w

Suggest an improvement
Source
https://github.com/advisories/GHSA-f9m8-cv68-674w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-f9m8-cv68-674w/GHSA-f9m8-cv68-674w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f9m8-cv68-674w
Aliases
Published
2026-10-08T16:30:53Z
Modified
2026-10-08T16:45:19Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N CVSS Calculator
Summary
AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so a cookie can be set for co.uk
Details

Impact

The cookie store decides whether a Domain attribute may be accepted using only the domain-matching rule of RFC 6265 Section 5.1.3, which asks whether the request host is the domain or ends with a dot followed by it. Section 5.3 step 5, which additionally requires rejecting a Domain that is a public suffix, is not implemented anywhere in the client.

So a host under a multi-label public suffix can set a cookie for the suffix itself, and the store then hands it to every other host under that suffix:

attacker.co.uk  ->  Set-Cookie: SID=attacker-value; Domain=co.uk; Path=/
bank.co.uk      ->  Cookie: SID=attacker-value

Domain=uk works the same way. The attacker needs only a site under the same suffix as the victim, which for suffixes such as co.uk, com.au, or github.io is trivially obtainable.

Depending on what the application does with the cookie, this is session fixation, or it overwrites a session the victim site set, or it lets the attacker plant a value the victim site trusts.

Affected versions

  • 3.x: up to and including 3.0.12
  • 2.x: up to and including 2.16.0

Relationship to CVE-2026-55688

CVE-2026-55688 (GHSA-m452-q8c9-rg2f) covered the direct form of this, where a host sets a Domain naming an unrelated host, and that form is genuinely fixed: attacker.co.uk can no longer set Domain=bank.co.uk, and this was verified as a control. What that fix did not add is the public suffix test, so setting Domain=co.uk still reaches bank.co.uk. This advisory covers only the residual.

Patches

Fixed in 3.0.13 on the 3.x line. The ICANN section of the Mozilla public suffix list is bundled with the client and a Domain matching it is rejected, honouring the list's wildcard and exception rules. The list is data and goes stale, so a suffix added upstream after a release is not recognised until the bundled copy is refreshed. The 2.x line is not yet fixed.

Workarounds

Do not share one CookieStore across origins that are not mutually trusted. Supplying a CookieStore implementation that rejects Domain values which are public suffixes also avoids it.

Details

ThreadSafeCookieStore.domainsMatch is requestDomain.equals(cookieDomain) || requestDomain.endsWith('.' + cookieDomain). It is used both to accept a Domain on storage and to select cookies for a request, and neither call site consults a public suffix list. A search of the client for any public suffix or effective TLD handling returns nothing.

Database specific
{
    "cwe_ids": [
        "CWE-1275"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-08T16:30:53Z",
    "nvd_published_at": "2026-10-07T22:17:03Z",
    "severity": "MODERATE"
}
References

Affected packages

Maven / org.asynchttpclient:async-http-client

Package

Name
org.asynchttpclient:async-http-client
View open source insights on deps.dev
Purl
pkg:maven/org.asynchttpclient/async-http-client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
3.0.13

Affected versions

3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.0.10
3.0.11
3.0.12

Database specific

last_known_affected_version_range
"<= 3.0.12"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-f9m8-cv68-674w/GHSA-f9m8-cv68-674w.json"

Maven / org.asynchttpclient:async-http-client

Package

Name
org.asynchttpclient:async-http-client
View open source insights on deps.dev
Purl
pkg:maven/org.asynchttpclient/async-http-client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.16.1

Affected versions

2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.40
2.1.0-alpha1
2.1.0-alpha2
2.1.0-alpha3
2.1.0-alpha4
2.1.0-alpha5
2.1.0-alpha6
2.1.0-alpha7
2.1.0-alpha8
2.1.0-alpha9
2.1.0-alpha10
2.1.0-alpha11
2.1.0-alpha12
2.1.0-alpha13
2.1.0-alpha14
2.1.0-alpha15
2.1.0-alpha16
2.1.0-alpha17
2.1.0-alpha18
2.1.0-alpha19
2.1.0-alpha20
2.1.0-alpha21
2.1.0-alpha22
2.1.0-alpha23
2.1.0-alpha24
2.1.0-alpha25
2.1.0-alpha26
2.1.0-RC1
2.1.0-RC2
2.1.0-RC3
2.1.0-RC4
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.6.0
2.7.0
2.8.0
2.8.1
2.9.0
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.14.5
2.15.0
2.16.0

Database specific

last_known_affected_version_range
"<= 2.16.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-f9m8-cv68-674w/GHSA-f9m8-cv68-674w.json"