Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2jwh-9rmr-j4xf | AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHeader (Bypass of CVE-2024-53990 Fix) |
Fri, 09 Oct 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Asynchttpclient Project
Asynchttpclient Project async-http-client |
|
| Vendors & Products |
Asynchttpclient Project
Asynchttpclient Project async-http-client |
Thu, 08 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. In the affected execution path, setHeader, addHeader, Cookie header, and CookieStore control or expose the vulnerable behavior. This issue is fixed in version 3.0.14. | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14. |
Wed, 07 Oct 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. In the affected execution path, setHeader, addHeader, Cookie header, and CookieStore control or expose the vulnerable behavior. This issue is fixed in version 3.0.14. | |
| Title | AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHeader (Bypass of CVE-2024-53990 Fix) | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T16:08:44.837Z
Reserved: 2026-10-07T14:34:14.817Z
Link: CVE-2026-107228
Updated: 2026-10-08T16:08:36.979Z
Status : Awaiting Analysis
Published: 2026-10-07T21:17:14.457
Modified: 2026-10-08T20:35:31.200
Link: CVE-2026-107228
No data.
OpenCVE Enrichment
Updated: 2026-10-09T07:30:17Z
-
CWE-287
Improper Authentication
Github GHSA