{"id":"CVE-2026-107229","summary":"AsyncHttpClient: Incomplete origin checks in the default cookie store allow cookie tossing onto public-suffix and IP-address hosts","details":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie Domain attributes. Missing private-section and default public-suffix rules, absent A-label normalization, locale-sensitive lowercasing, public-suffix host-only handling, and numeric or IP host checks allow one origin to store a cookie later sent to another origin. Applications sharing one client across trust domains can therefore receive attacker-injected cookies and may be exposed to session fixation. This issue is fixed in version 3.0.14.","aliases":["GHSA-qjr7-w8pj-pmv9"],"modified":"2026-10-09T07:06:48.460140436Z","published":"2026-10-07T20:57:36.676Z","database_specific":{"cwe_ids":["CWE-1275","CWE-384"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107229.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14"},{"type":"ADVISORY","url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-qjr7-w8pj-pmv9"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107229.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107229"},{"type":"FIX","url":"https://github.com/AsyncHttpClient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asynchttpclient/async-http-client","events":[{"introduced":"a374830195d5c36946cc73a8b1b91d1583514841"},{"introduced":"8e4069cf3c92abe099db5fb13378ac2fe9e1fd3b"},{"fixed":"7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9"},{"fixed":"bec30bb3d27ad13f069f72b37351c61bff3394ff"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"3.0.11"},{"fixed":"3.0.14"},{"introduced":"2.16.0"},{"last_affected":"2.16.1"}]}}],"versions":["async-http-client-project-3.0.13","async-http-client-project-3.0.12","async-http-client-project-3.0.11"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["33087627559746334733055649192559444069","174284107661717695606729850883713530180","109145464982146699055316524616666545751","148339253466060478337098028124600990708"],"threshold":0.9},"id":"CVE-2026-107229-0d88ebe5","signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"file":"client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java"}},{"source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"file":"client/src/test/java/org/asynchttpclient/netty/handler/intercept/RedirectCookieRotationTest.java","function":"handle"},"deprecated":false,"digest":{"length":1560,"function_hash":"276864848472423719414757550086002885130"},"id":"CVE-2026-107229-17dc17fe","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"length":1863,"function_hash":"106814611372285579444677840612955435961"},"id":"CVE-2026-107229-28734980","signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"function":"configureHandler","file":"client/src/test/java/org/asynchttpclient/netty/handler/intercept/RedirectCookieRotationTest.java"}},{"signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"function":"domainsMatch","file":"client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java"},"deprecated":false,"digest":{"function_hash":"115940402890807429955760986565602637476","length":120},"id":"CVE-2026-107229-3b2325ff","signature_type":"Function"},{"target":{"file":"client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java"},"deprecated":false,"digest":{"line_hashes":["247694179419932114093793702843491239082","57211957134461112860058773182379275995","216080824044332933328412906970202310411","59405819059463446559593025959235047176","299312744527592712421706445106863422673","75894720239402336613015023292848159247","185015237781816424532507524630143645433","253708435705059957798605917225224170088","97115343038153427764245928886389711088","191539296830046224750723598236008461408","239775462559452874105975531493182810347","313720678631869063820877865354667288142","325688326483478929585940537661204293577","173943898435057278053090360309407341145","4709180722342919918902290985069289443","110747029792159351215596397069884192432","95159359966140867219714707020408453500","109533612602304150515050995468715208724","62656153810684508246929104297934449918","74120616183125299194991081336514149766","4052592507583876337734154454068745777","30631161873019928365998941926373366929","247210696621327228578754474573598524058","208439124980247623559633204981053315615","17362021996759348601791357669588383829","25720493374319289139560276406994158433","144597446968475953813647189542002899657","228253584051373068169897942583451754934","233235274460114274822121487217721683928"],"threshold":0.9},"id":"CVE-2026-107229-3bd8224c","signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9"},{"id":"CVE-2026-107229-641ce594","signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"function":"add","file":"client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java"},"deprecated":false,"digest":{"length":913,"function_hash":"265317588963511779018970140852205965214"}},{"source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"file":"client/src/main/java/org/asynchttpclient/netty/handler/intercept/Interceptors.java","function":"exitAfterIntercept"},"deprecated":false,"digest":{"function_hash":"330563532898594570748645521577256742314","length":2332},"id":"CVE-2026-107229-6ec36339","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"file":"client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java","function":"requestDomain"},"deprecated":false,"digest":{"length":79,"function_hash":"312370062830392926848782787092014571970"},"id":"CVE-2026-107229-71714fc7","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"function":"computeInitialScheme","file":"client/src/main/java/org/asynchttpclient/uri/UriParser.java"},"deprecated":false,"digest":{"length":333,"function_hash":"211172431976494218535757894318157688808"},"id":"CVE-2026-107229-74066133","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"function":"cookieDomain","file":"client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java"},"deprecated":false,"digest":{"length":366,"function_hash":"6865819958901056120144211982719562395"},"id":"CVE-2026-107229-7fbc27f4","signature_type":"Function"},{"target":{"file":"client/src/test/java/org/asynchttpclient/netty/handler/intercept/RedirectCookieRotationTest.java"},"deprecated":false,"digest":{"line_hashes":["194085218971423918351672527001465036859","141336872609680292515842545408262225761","236115854174370893464950668114956564614","11573342555884394794431823572959399438","242262271946618261313490570888123214600","48316514767524736772429414268698866344","287207809435390462090876377761222310749","4933259814561582187698866590100107738","48406188592455954159449924487562041820","298672238892429704270655493708135406415","144128759005398106200039476435346443390"],"threshold":0.9},"id":"CVE-2026-107229-8d70fc1e","signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"file":"client/src/test/java/org/asynchttpclient/cookie/PublicSuffixCookieTest.java"},"deprecated":false,"digest":{"line_hashes":["256976497602142119066324708626363925459","86741187361099052887177111067828616794","313914054448447323205948378595309688502","167957111778866701078860108538583502237","149361785834247464982042831524132464278","275622026211626529050788549752293225286","274105389113473717578584128717452691847","214210419419227967164426280539281432260","187726570627759142628813498970152384484","339437952405093852219468358342782624928","304324893235715318322205067908671500642"],"threshold":0.9},"id":"CVE-2026-107229-951b0f84"},{"signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"function":"get","file":"client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java"},"deprecated":false,"digest":{"length":396,"function_hash":"290711153745038152910324839129358776332"},"id":"CVE-2026-107229-ad56d4c3","signature_type":"Function"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"function":"matchingDoesNotDependOnTheDefaultLocale","file":"client/src/test/java/org/asynchttpclient/cookie/PublicSuffixCookieTest.java"},"deprecated":false,"digest":{"function_hash":"1023412899023067134538991106637957975","length":462},"id":"CVE-2026-107229-bbf4b583"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"file":"client/src/main/java/org/asynchttpclient/cookie/ThreadSafeCookieStore.java"},"deprecated":false,"digest":{"line_hashes":["174135115827321605688648560259149190926","296632240457193039721626246023267517993","208473677295071005981444236329111900427","54472894365051758838080820115505025795","312910604288998101704086719912592704612","11234675333072737720347482587242135801","130846461444494649932487497157587135491","167955448420678513278123579041915286157","265982438466981375203183896434691899000","279379031461672288442368596249162255124","10928255603295237853162815325285886657","132225577470641782781375161952402436318","313158642643768397744730229846186811439","208947099844355703655791073678716881198","168467507294931930693340425927954450842","4897861155229930331298258652756611504","47913561250901428473763436035396304620","185584592581581086792200876018648799785","251674873430826288757035124759273503050","30483950268209270079395523844370814008","113119896697765934241192951918636651482","101384915292668625134629660356451778279","112413554918931264338179563940130289539","57089443874382053284579200274847746064","40984194156150570535910081713561760865","249115769572635418192576401341938543280","266653017854504597785695437514758024105","183568569644043229459495129598891836116","35902536387443472121516728201853258441","162056186937370362122811838035742898454","311049525285794685723264305745708170986","129349975429647033139101295661628000491","16654500804302709650693920544626835771","123532522852325830043277178959754771285"],"threshold":0.9},"id":"CVE-2026-107229-cf43f84f"},{"target":{"file":"client/src/main/java/org/asynchttpclient/cookie/PublicSuffixList.java","function":"isPublicSuffix"},"deprecated":false,"digest":{"function_hash":"298986444797709434117966201905479988645","length":475},"id":"CVE-2026-107229-e85a4520","signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9"},{"target":{"file":"client/src/main/java/org/asynchttpclient/netty/handler/intercept/CallerCookies.java","function":"of"},"deprecated":false,"digest":{"function_hash":"216529552554099928734629029204801405992","length":896},"id":"CVE-2026-107229-ee8f22f7","signature_type":"Function","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9"},{"signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"file":"client/src/main/java/org/asynchttpclient/cookie/PublicSuffixList.java"},"deprecated":false,"digest":{"line_hashes":["163460617041448915435106570125163341177","220693160014543210602000580773444817323","325972425223094014321290181614380074682","170990231085234808916357038511038412227","71761630122404921022274347410132561970","179691288432850565026342880730492233152","106768672560629387791532116331993506400","235026464766744766020642873036220476567","139892491487293749831709586418903057307","295062653115761824623142948979136043232","295387080296510626730213342130333809618","9293357313110225933203648058232993985","153309781410899137015980477577417120231","648867112131648685003376047807699052","167628217003687880709534423656366522074","264111976902312291337484820911767945997","291981110659552161648943657997973306610","333275199811182498877548502249392879602","300534355349738429695812239761351601032","291835942639428180096515659950965175178","71672733182417891482004804307179310506","117092101910584726925119959069510813894","44674223638796070971011854980683711845","253252397768399543515749821963214578802","45851374566771631151152579095951606809","233374085794502757110388840974997936507","18804661826057169267913436296366649171","149764423673691890771710714194679048040","282787580347465578637188518929430460969","204424926367979055994395256887273834446","218075727629212283065108900863705824394","15689139872896914115608196315679095318","177690024590699536347165037699011076547"],"threshold":0.9},"id":"CVE-2026-107229-f0227e5f","signature_type":"Line"},{"digest":{"line_hashes":["303465232377018570292147095408148422132","68540916644121381074444004811484803651","42347147065416192873448999259098185416","275184213013584246598154864022780096429","16661186105824384935564268691375229986","84825862606863240363320174168073169201","243465948167404466498370112425698889302"],"threshold":0.9},"id":"CVE-2026-107229-fa04ea08","signature_type":"Line","signature_version":"v1","source":"https://github.com/asynchttpclient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","target":{"file":"client/src/main/java/org/asynchttpclient/uri/UriParser.java"},"deprecated":false}],"vanir_signatures_modified":"2026-10-09T07:06:48Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107229.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"}]}