{"affected":[{"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-m452-q8c9-rg2f/GHSA-m452-q8c9-rg2f.json"},"package":{"ecosystem":"Maven","name":"org.asynchttpclient:async-http-client","purl":"pkg:maven/org.asynchttpclient/async-http-client"},"ranges":[{"events":[{"introduced":"3.0.0.Beta1"},{"fixed":"3.0.11"}],"type":"ECOSYSTEM"}],"versions":["3.0.0","3.0.0.Beta1","3.0.0.Beta2","3.0.0.Beta3","3.0.1","3.0.10","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9"]},{"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-m452-q8c9-rg2f/GHSA-m452-q8c9-rg2f.json"},"package":{"ecosystem":"Maven","name":"org.asynchttpclient:async-http-client","purl":"pkg:maven/org.asynchttpclient/async-http-client"},"ranges":[{"events":[{"introduced":"2.0.0"},{"fixed":"2.16.0"}],"type":"ECOSYSTEM"}],"versions":["2.0.0","2.0.1","2.0.10","2.0.11","2.0.12","2.0.13","2.0.14","2.0.15","2.0.16","2.0.17","2.0.18","2.0.19","2.0.2","2.0.20","2.0.21","2.0.22","2.0.23","2.0.24","2.0.25","2.0.26","2.0.27","2.0.28","2.0.29","2.0.3","2.0.30","2.0.31","2.0.32","2.0.33","2.0.34","2.0.35","2.0.36","2.0.37","2.0.38","2.0.39","2.0.4","2.0.40","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.1.0","2.1.0-RC1","2.1.0-RC2","2.1.0-RC3","2.1.0-RC4","2.1.0-alpha1","2.1.0-alpha10","2.1.0-alpha11","2.1.0-alpha12","2.1.0-alpha13","2.1.0-alpha14","2.1.0-alpha15","2.1.0-alpha16","2.1.0-alpha17","2.1.0-alpha18","2.1.0-alpha19","2.1.0-alpha2","2.1.0-alpha20","2.1.0-alpha21","2.1.0-alpha22","2.1.0-alpha23","2.1.0-alpha24","2.1.0-alpha25","2.1.0-alpha26","2.1.0-alpha3","2.1.0-alpha4","2.1.0-alpha5","2.1.0-alpha6","2.1.0-alpha7","2.1.0-alpha8","2.1.0-alpha9","2.1.1","2.1.2","2.10.0","2.10.1","2.10.2","2.10.3","2.10.4","2.10.5","2.11.0","2.12.0","2.12.1","2.12.2","2.12.3","2.12.4","2.14.5","2.15.0","2.2.0","2.2.1","2.3.0","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.4.7","2.4.8","2.4.9","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.6.0","2.7.0","2.8.0","2.8.1","2.9.0"]}],"aliases":["CVE-2026-55688"],"database_specific":{"cwe_ids":["CWE-1275"],"github_reviewed":true,"github_reviewed_at":"2026-08-26T14:35:52Z","nvd_published_at":"2026-07-01T20:17:11Z","severity":"MODERATE"},"details":"### Impact\n A **cookie tossing / cookie injection** issue (CWE-1275). `ThreadSafeCookieStore` stored a cookie under the value of its `Domain` attribute without verifying that the responding host is allowed to set a cookie for that domain (RFC 6265 §5.3 step 6). A host the client connects to can therefore plant a cookie scoped to an unrelated domain, and the client will then send that cookie on later requests to that domain.\n\n### Who is Impacted\nApplications that use a single `AsyncHttpClient` instance - and thus the default, shared `CookieStore` - to reach **both** an attacker-influenced host and a trusted host. Typical exposure: crawlers, link-preview / webhook fetchers, SSRF-style \"fetch this URL\" features, multi-backend aggregators, or following redirects to an attacker-controlled host. The attacker can *write* a cookie the client presents to the victim host (session fixation, overwriting a session id / CSRF-token cookie); they cannot *read* the victim host's cookies. Applications that talk only to a fixed trusted backend, or that disable/scope the cookie store, are not exposed.\n\n### Patches\nFixed in 3.0.11 and 2.16.0\n\n### Workarounds\n- Disable the cookie store (setCookieStore(null)) when cookies are not needed; or\n- Use a separate AsyncHttpClient (separate cookie store) per trust domain so an attacker-influenced host and a trusted host never share a jar\n- Supply a custom CookieStore whose add(Uri, Cookie) rejects cookies whose Domain is not domain-matched by the request host.","id":"GHSA-m452-q8c9-rg2f","modified":"2026-09-10T03:51:14.308963751Z","published":"2026-08-26T14:35:52Z","references":[{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-m452-q8c9-rg2f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55688"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/pull/2196"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/pull/2199"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/commit/8e4069cf3c92abe099db5fb13378ac2fe9e1fd3b"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/commit/e6955c1e3951cf80e286981d064f6c926ce33f47"},{"type":"PACKAGE","url":"https://github.com/AsyncHttpClient/async-http-client"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.0"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.11"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/08/msg00011.html"}],"schema_version":"1.9.0","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N","type":"CVSS_V3"}],"summary":"AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore"}