{"id":"CVE-2026-107228","summary":"AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHeader (Bypass of CVE-2024-53990 Fix)","details":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14.","aliases":["GHSA-2jwh-9rmr-j4xf"],"modified":"2026-10-09T07:06:49.642911723Z","published":"2026-10-07T20:54:34.703Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-287"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107228.json"},"references":[{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"},{"type":"ADVISORY","url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-2jwh-9rmr-j4xf"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107228.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107228"},{"type":"FIX","url":"https://github.com/AsyncHttpClient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asynchttpclient/async-http-client","events":[{"introduced":"9a771c7b40e716ca77a3cad691545b29ff64bfd3"},{"introduced":"927333da38413759027ccc22a93621da21e7468a"},{"fixed":"fd9763620725126c1c8bb0af1ceb9a7523099a5f"},{"fixed":"bec30bb3d27ad13f069f72b37351c61bff3394ff"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.0.14"},{"introduced":"2.1.0"},{"last_affected":"2.16.1"}]}}],"versions":["async-http-client-project-3.0.13","async-http-client-project-3.0.12","async-http-client-project-3.0.11","async-http-client-project-3.0.10","async-http-client-project-3.0.9","async-http-client-project-3.0.8","async-http-client-project-3.0.7","async-http-client-project-3.0.6","async-http-client-project-3.0.5","async-http-client-project-3.0.4","async-http-client-project-3.0.3","async-http-client-project-3.0.2","async-http-client-project-3.0.1","async-http-client-project-3.0.0"],"database_specific":{"vanir_signatures_modified":"2026-10-09T07:06:49Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107228.json","vanir_signatures":[{"source":"https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f","target":{"file":"client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java","function":"exitAfterHandlingRedirect"},"deprecated":false,"digest":{"function_hash":"313603061959576688548777385639564162930","length":4032},"id":"CVE-2026-107228-02faa2b6","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f","target":{"file":"client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java"},"deprecated":false,"digest":{"line_hashes":["287069903123008852882841889913397143074","191838875415762874642176763336217022120","113797460107587920888555199139928196212","103804818187391539090885865114205550594","182346267471002759321306061961817230341","144714281036865929407480854553598484279","288814041628016585885127686075437221844","213390825785352973793750739874174814404","70788294503808365467827103474380359682","275145303984969573359390435236421562021","314062207477349738109207967216326617891","242552941518224108318336312870509912610"],"threshold":0.9},"id":"CVE-2026-107228-3b2e8a97","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["131813821150373505620774268007306264503","193621198389632918908923865843040210504","208320048997645960997154809074017260448","34308804407403879095937292396502725315","237189984971397957599218815152331293078","160044918139477595106355276220402077707","60047714855156046610284336938024895363","52998305829158081851656410722162708070","63362322890425750796743428220565539738","201765198644889074114671127464533685051","64880555049755556472985015206633017435","24736618307450635658946862674823019712","88111044465016833162555050742681178962","52771326476915651147735692907963057765","83349843552220294363276974189387685097","237845449785090346776314012687950506052","96349964609859721993763064892438406574","295888715283424355124800102279176408284","199521661099934714503105398657266481865","132157563206171442787170228041694564597"],"threshold":0.9},"id":"CVE-2026-107228-7cc4e1b4","signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f","target":{"file":"client/src/main/java/org/asynchttpclient/netty/request/NettyRequestFactory.java"}},{"digest":{"line_hashes":["239690584058812298211859179517373029985","16044321736028551889640708483344368397","199914722048295196205805804439511726906"],"threshold":0.9},"id":"CVE-2026-107228-a01aca0a","signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f","target":{"file":"client/src/test/java/org/asynchttpclient/netty/handler/intercept/RedirectCookieRotationTest.java"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"18351566744866301822787804471387203771","length":603},"id":"CVE-2026-107228-a1635f8a","signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f","target":{"function":"propagatedHeaders","file":"client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java"}},{"digest":{"line_hashes":["153227647759387577818628900119438660106","41572496521538229573533027958985371551","307299973282187188779667715712473709632","243508187588480454342307296868628008686","250529020770641903196583267582094170694","192587502608494044156846631721658155088","127951931999617742542890735157417724090","247694179419932114093793702843491239082","149344885802355013855684752970707055196","212900781779656746574786280417023274013","212408094802880442371339501342517618011","1030524342785002509039580950146360854","100892034106718292396103506302439123028","177363156482294000041482317455850921267","37020120704538961883271891393705791545","269691904290460280372371368876051462203","207398947181489958571551128607706751317","312149197585668114129080980000884922687","104119789342903949346560542298742739645","193343541369458030859272478299878306108","138375113865737918058242639310936678376","262836725046648004713320628983202047971","126662453710966849278202533947481184509","119756437360289680115624826811648085903","259139591301458106063580406993904455456"],"threshold":0.9},"id":"CVE-2026-107228-d1b91c76","signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f","target":{"file":"client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java"},"deprecated":false},{"digest":{"length":278,"function_hash":"327884523773490273323951324865420312209"},"id":"CVE-2026-107228-da00feba","signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f","target":{"file":"client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java","function":"refresh"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f","target":{"file":"client/src/test/java/org/asynchttpclient/netty/handler/intercept/AuthRetryCookieTest.java"},"deprecated":false,"digest":{"line_hashes":["286446077946549461972192985029569759549","203229685696938595454879280339250205871","155550159802052143491768614918434571899"],"threshold":0.9},"id":"CVE-2026-107228-de42cf23"},{"digest":{"function_hash":"9500407417655056984423392268729190784","length":1049},"id":"CVE-2026-107228-f0ed2c83","signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f","target":{"file":"client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java","function":"of"},"deprecated":false},{"id":"CVE-2026-107228-fee08627","signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f","target":{"function":"newNettyRequest","file":"client/src/main/java/org/asynchttpclient/netty/request/NettyRequestFactory.java"},"deprecated":false,"digest":{"function_hash":"76738329251562025766797757408856436878","length":3774}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}