CVE-2026-55688: CWE-1275: Sensitive Cookie with Improper SameSite Attribute in AsyncHttpClient async-http-client
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and from 3.0.0.Beta1 prior to 3.0.11, ThreadSafeCookieStore stored a cookie under the value of its Domain attribute without verifying that the responding host is allowed to set a cookie for that domain, leading to a cookie tossing / cookie injection issue. A host the client connects to can therefore plant a cookie scoped to an unrelated domain, and the client will then send that cookie on later requests to that domain. Applications that use a single AsyncHttpClient instance - and thus the default, shared CookieStore - to reach both an attacker-influenced host and a trusted host are impacted. This issue has been fixed in versions 2.16.0 and 3.0.11.
AI Analysis
Technical Summary
The AsyncHttpClient library suffers from a cookie tossing/cookie injection vulnerability due to ThreadSafeCookieStore storing cookies without verifying the domain authorization of the responding host. This flaw allows an attacker-controlled host to set cookies for unrelated domains, which the client will send on later requests, potentially leading to unintended cookie sharing across domains. The vulnerability affects versions from 2.0.0 up to but not including 2.16.0 and from 3.0.0.Beta1 up to but not including 3.0.11. The issue is resolved in versions 2.16.0 and 3.0.11.
Potential Impact
An attacker controlling a host that the client connects to can inject cookies scoped to unrelated domains into the client's cookie store. This may cause the client to send attacker-injected cookies to trusted domains, potentially leading to session confusion or other unintended behaviors. The CVSS score is 4.0 (medium severity) with network attack vector, high attack complexity, no privileges required, no user interaction, and impact limited to integrity.
Mitigation Recommendations
Upgrade AsyncHttpClient to version 2.16.0 or later, or 3.0.11 or later, where this vulnerability is fixed. There is no indication of alternative mitigations or temporary fixes. Patch status is not explicitly confirmed in the vendor advisory, but the description states the issue is fixed in these versions.
CVE-2026-55688: CWE-1275: Sensitive Cookie with Improper SameSite Attribute in AsyncHttpClient async-http-client
Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and from 3.0.0.Beta1 prior to 3.0.11, ThreadSafeCookieStore stored a cookie under the value of its Domain attribute without verifying that the responding host is allowed to set a cookie for that domain, leading to a cookie tossing / cookie injection issue. A host the client connects to can therefore plant a cookie scoped to an unrelated domain, and the client will then send that cookie on later requests to that domain. Applications that use a single AsyncHttpClient instance - and thus the default, shared CookieStore - to reach both an attacker-influenced host and a trusted host are impacted. This issue has been fixed in versions 2.16.0 and 3.0.11.
CVSS v3.1
Score 4.0medium
Affected software
pkg:maven/org.asynchttpclient/async-http-clientRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The AsyncHttpClient library suffers from a cookie tossing/cookie injection vulnerability due to ThreadSafeCookieStore storing cookies without verifying the domain authorization of the responding host. This flaw allows an attacker-controlled host to set cookies for unrelated domains, which the client will send on later requests, potentially leading to unintended cookie sharing across domains. The vulnerability affects versions from 2.0.0 up to but not including 2.16.0 and from 3.0.0.Beta1 up to but not including 3.0.11. The issue is resolved in versions 2.16.0 and 3.0.11.
Potential Impact
An attacker controlling a host that the client connects to can inject cookies scoped to unrelated domains into the client's cookie store. This may cause the client to send attacker-injected cookies to trusted domains, potentially leading to session confusion or other unintended behaviors. The CVSS score is 4.0 (medium severity) with network attack vector, high attack complexity, no privileges required, no user interaction, and impact limited to integrity.
Mitigation Recommendations
Upgrade AsyncHttpClient to version 2.16.0 or later, or 3.0.11 or later, where this vulnerability is fixed. There is no indication of alternative mitigations or temporary fixes. Patch status is not explicitly confirmed in the vendor advisory, but the description states the issue is fixed in these versions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-17T00:13:10.650Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a456fd127e9c79719097e6d
Added to database: 07/01/2026, 19:51:45 UTC
Last enriched: 08/07/2026, 13:26:23 UTC
Last updated: 08/15/2026, 12:41:10 UTC
Views: 92
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.