
🔴 AsyncHttpClient, Cookie Override Vulnerability, #CVE-2026-107228 (High) -DC-Oct2026-2934 https://dailycve.com/asynchttpclient-cookie-override-vulnerability-cve-2026-107228-high-dc-oct2026-2934/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🔴 AsyncHttpClient, Cookie Override Vulnerability, #CVE-2026-107228 (High) -DC-Oct2026-2934 https://dailycve.com/asynchttpclient-cookie-override-vulnerability-cve-2026-107228-high-dc-oct2026-2934/