ghsa-m452-q8c9-rg2f

CVSS 4.0 osv_maven
Description

### Impact A **cookie tossing / cookie injection** issue (CWE-1275). `ThreadSafeCookieStore` stored a cookie under the value of its `Domain` attribute without verifying that the responding host is allowed to set a cookie for that domain (RFC 6265 §5.3 step 6). A host the client connects to can therefore plant a cookie scoped to an unrelated domain, and the client will then send that cookie on later requests to that domain. ### Who is Impacted Applications that use a single `AsyncHttpClient` instance - and thus the default, shared `CookieStore` - to reach **both** an attacker-influenced host and a trusted host. Typical exposure: crawlers, link-preview / webhook fetchers, SSRF-style "fetch this URL" features, multi-backend aggregators, or following redirects to an attacker-controlled host. The attacker can *write* a cookie the client presents to the victim host (session fixation, overwriting a session id / CSRF-token cookie); they cannot *read* the victim host's cookies. Applications that talk only to a fixed trusted backend, or that disable/scope the cookie store, are not exposed. ### Patches Fixed in 3.0.11 and 2.16.0 ### Workarounds - Disable the cookie store (setCookieStore(null)) when cookies are not needed; or - Use a separate AsyncHttpClient (separate cookie store) per trust domain so an attacker-influenced host and a trusted host never share a jar - Supply a custom CookieStore whose add(Uri, Cookie) rejects cookies whose Domain is not domain-matched by the request host.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-m452-q8c9-rg2f/GHSA-m452-q8c9-rg2f.json"
      },
      "package": {
        "ecosystem": "Maven",
        "name": "org.asynchttpclient:async-http-client",
        "purl": "pkg:maven/org.asynchttpclient/async-http-client"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.0.0.Beta1"
            },
            {
              "fixed": "3.0.11"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "3.0.0",
        "3.0.0.Beta1",
        "3.0.0.Beta2",
        "3.0.0.Beta3",
        "3.0.1",
        "3.0.10",
        "3.0.2",
        "3.0.3",
        "3.0.4",
        "3.0.5",
        "3.0.6",
        "3.0.7",
        "3.0.8",
        "3.0.9"
      ]
    },
    {
      "database_specific": {
        "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-m452-q8c9-rg2f/GHSA-m452-q8c9-rg2f.json"
      },
      "package": {
        "ecosystem": "Maven",
        "name": "org.asynchttpclient:async-http-client",
        "purl": "pkg:maven/org.asynchttpclient/async-http-client"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.0.0"
            },
            {
              "fixed": "2.16.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "2.0.0",
        "2.0.1",
        "2.0.10",
        "2.0.11",
        "2.0.12",
        "2.0.13",
        "2.0.14",
        "2.0.15",
        "2.0.16",
        "2.0.17",
        "2.0.18",
        "2.0.19",
        "2.0.2",
        "2.0.20",
        "2.0.21",
        "2.0.22",
        "2.0.23",
        "2.0.24",
        "2.0.25",
        "2.0.26",
        "2.0.27",
        "2.0.28",
        "2.0.29",
        "2.0.3",
        "2.0.30",
        "2.0.31",
        "2.0.32",
        "2.0.33",
        "2.0.34",
        "2.0.35",
        "2.0.36",
        "2.0.37",
        "2.0.38",
        "2.0.39",
        "2.0.4",
        "2.0.40",
        "2.0.5",
        "2.0.6",
        "2.0.7",
        "2.0.8",
        "2.0.9",
        "2.1.0",
        "2.1.0-RC1",
        "2.1.0-RC2",
        "2.1.0-RC3",
        "2.1.0-RC4",
        "2.1.0-alpha1",
        "2.1.0-alpha10",
        "2.1.0-alpha11",
        "2.1.0-alpha12",
        "2.1.0-alpha13",
        "2.1.0-alpha14",
        "2.1.0-alpha15",
        "2.1.0-alpha16",
        "2.1.0-alpha17",
        "2.1.0-alpha18",
        "2.1.0-alpha19",
        "2.1.0-alpha2",
        "2.1.0-alpha20",
        "2.1.0-alpha21",
        "2.1.0-alpha22",
        "2.1.0-alpha23",
        "2.1.0-alpha24",
        "2.1.0-alpha25",
        "2.1.0-alpha26",
        "2.1.0-alpha3",
        "2.1.0-alpha4",
        "2.1.0-alpha5",
        "2.1.0-alpha6",
        "2.1.0-alpha7",
        "2.1.0-alpha8",
        "2.1.0-alpha9",
        "2.1.1",
        "2.1.2",
        "2.10.0",
        "2.10.1",
        "2.10.2",
        "2.10.3",
        "2.10.4",
        "2.10.5",
        "2.11.0",
        "2.12.0",
        "2.12.1",
        "2.12.2",
        "2.12.3",
        "2.12.4",
        "2.14.5",
        "2.15.0",
        "2.2.0",
        "2.2.1",
        "2.3.0",
        "2.4.0",
        "2.4.1",
        "2.4.2",
        "2.4.3",
        "2.4.4",
        "2.4.5",
        "2.4.6",
        "2.4.7",
        "2.4.8",
        "2.4.9",
        "2.5.0",
        "2.5.1",
        "2.5.2",
        "2.5.3",
        "2.5.4",
        "2.6.0",
        "2.7.0",
        "2.8.0",
        "2.8.1",
        "2.9.0"
      ]
    }
  ],
  "aliases": [
    "CVE-2026-55688"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1275"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-08-26T14:35:52Z",
    "nvd_published_at": "2026-07-01T20:17:11Z",
    "severity": "MODERATE"
  },
  "details": "### Impact\n A **cookie tossing / cookie injection** issue (CWE-1275). `ThreadSafeCookieStore` stored a cookie under the value of its `Domain` attribute without verifying that the responding host is allowed to set a cookie for that domain (RFC 6265 §5.3 step 6). A host the client connects to can therefore plant a cookie scoped to an unrelated domain, and the client will then send that cookie on later requests to that domain.\n\n### Who is Impacted\nApplications that use a single `AsyncHttpClient` instance - and thus the default, shared `CookieStore` - to reach **both** an attacker-influenced host and a trusted host. Typical exposure: crawlers, link-preview / webhook fetchers, SSRF-style \"fetch this URL\" features, multi-backend aggregators, or following redirects to an attacker-controlled host. The attacker can *write* a cookie the client presents to the victim host (session fixation, overwriting a session id / CSRF-token cookie); they cannot *read* the victim host's cookies. Applications that talk only to a fixed trusted backend, or that disable/scope the cookie store, are not exposed.\n\n### Patches\nFixed in 3.0.11 and 2.16.0\n\n### Workarounds\n- Disable the cookie store (setCookieStore(null)) when cookies are not needed; or\n- Use a separate AsyncHttpClient (separate cookie store) per trust domain so an attacker-influenced host and a trusted host never share a jar\n- Supply a custom CookieStore whose add(Uri, Cookie) rejects cookies whose Domain is not domain-matched by the request host.",
  "id": "GHSA-m452-q8c9-rg2f",
  "modified": "2026-09-10T03:51:14.308963751Z",
  "published": "2026-08-26T14:35:52Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-m452-q8c9-rg2f"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55688"
    },
    {
      "type": "WEB",
      "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2196"
    },
    {
      "type": "WEB",
      "url": "https://github.com/AsyncHttpClient/async-http-client/pull/2199"
    },
    {
      "type": "WEB",
      "url": "https://github.com/AsyncHttpClient/async-http-client/commit/8e4069cf3c92abe099db5fb13378ac2fe9e1fd3b"
    },
    {
      "type": "WEB",
      "url": "https://github.com/AsyncHttpClient/async-http-client/commit/e6955c1e3951cf80e286981d064f6c926ce33f47"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/AsyncHttpClient/async-http-client"
    },
    {
      "type": "WEB",
      "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.0"
    },
    {
      "type": "WEB",
      "url": "https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.11"
    },
    {
      "type": "WEB",
      "url": "https://lists.debian.org/debian-lts-announce/2026/08/msg00011.html"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore"
}
View JSON API Download JSON