{"id":"GHSA-f9m8-cv68-674w","summary":"AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so a cookie can be set for co.uk","details":"### Impact\nThe cookie store decides whether a `Domain` attribute may be accepted using only the domain-matching rule of RFC 6265 Section 5.1.3, which asks whether the request host is the domain or ends with a dot followed by it. Section 5.3 step 5, which additionally requires rejecting a `Domain` that is a public suffix, is not implemented anywhere in the client.\n\nSo a host under a multi-label public suffix can set a cookie for the suffix itself, and the store then hands it to every other host under that suffix:\n\n```\nattacker.co.uk  -\u003e  Set-Cookie: SID=attacker-value; Domain=co.uk; Path=/\nbank.co.uk      -\u003e  Cookie: SID=attacker-value\n```\n\n`Domain=uk` works the same way. The attacker needs only a site under the same suffix as the victim, which for suffixes such as `co.uk`, `com.au`, or `github.io` is trivially obtainable.\n\nDepending on what the application does with the cookie, this is session fixation, or it overwrites a session the victim site set, or it lets the attacker plant a value the victim site trusts.\n\n### Affected versions\n* 3.x: up to and including 3.0.12\n* 2.x: up to and including 2.16.0\n\n### Relationship to CVE-2026-55688\nCVE-2026-55688 (GHSA-m452-q8c9-rg2f) covered the direct form of this, where a host sets a `Domain` naming an unrelated host, and that form is genuinely fixed: `attacker.co.uk` can no longer set `Domain=bank.co.uk`, and this was verified as a control. What that fix did not add is the public suffix test, so setting `Domain=co.uk` still reaches `bank.co.uk`. This advisory covers only the residual.\n\n### Patches\nFixed in 3.0.13 on the 3.x line. The ICANN section of the Mozilla public suffix list is bundled with the client and a `Domain` matching it is rejected, honouring the list's wildcard and exception rules. The list is data and goes stale, so a suffix added upstream after a release is not recognised until the bundled copy is refreshed. The 2.x line is not yet fixed.\n\n### Workarounds\nDo not share one `CookieStore` across origins that are not mutually trusted. Supplying a `CookieStore` implementation that rejects `Domain` values which are public suffixes also avoids it.\n\n### Details\n`ThreadSafeCookieStore.domainsMatch` is `requestDomain.equals(cookieDomain) || requestDomain.endsWith('.' + cookieDomain)`. It is used both to accept a `Domain` on storage and to select cookies for a request, and neither call site consults a public suffix list. A search of the client for any public suffix or effective TLD handling returns nothing.","aliases":["CVE-2026-107280"],"modified":"2026-10-08T16:45:19.478132339Z","published":"2026-10-08T16:30:53Z","database_specific":{"github_reviewed_at":"2026-10-08T16:30:53Z","nvd_published_at":"2026-10-07T22:17:03Z","cwe_ids":["CWE-1275"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f9m8-cv68-674w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107280"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/commit/330267895fe0bdb41bbd027ea6b151d38ee7c23d"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f"},{"type":"PACKAGE","url":"https://github.com/AsyncHttpClient/async-http-client"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13"}],"affected":[{"package":{"name":"org.asynchttpclient:async-http-client","ecosystem":"Maven","purl":"pkg:maven/org.asynchttpclient/async-http-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.0.13"}]}],"versions":["3.0.0","3.0.1","3.0.10","3.0.11","3.0.12","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.0.12","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-f9m8-cv68-674w/GHSA-f9m8-cv68-674w.json"}},{"package":{"name":"org.asynchttpclient:async-http-client","ecosystem":"Maven","purl":"pkg:maven/org.asynchttpclient/async-http-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.16.1"}]}],"versions":["2.0.0","2.0.1","2.0.10","2.0.11","2.0.12","2.0.13","2.0.14","2.0.15","2.0.16","2.0.17","2.0.18","2.0.19","2.0.2","2.0.20","2.0.21","2.0.22","2.0.23","2.0.24","2.0.25","2.0.26","2.0.27","2.0.28","2.0.29","2.0.3","2.0.30","2.0.31","2.0.32","2.0.33","2.0.34","2.0.35","2.0.36","2.0.37","2.0.38","2.0.39","2.0.4","2.0.40","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.1.0","2.1.0-RC1","2.1.0-RC2","2.1.0-RC3","2.1.0-RC4","2.1.0-alpha1","2.1.0-alpha10","2.1.0-alpha11","2.1.0-alpha12","2.1.0-alpha13","2.1.0-alpha14","2.1.0-alpha15","2.1.0-alpha16","2.1.0-alpha17","2.1.0-alpha18","2.1.0-alpha19","2.1.0-alpha2","2.1.0-alpha20","2.1.0-alpha21","2.1.0-alpha22","2.1.0-alpha23","2.1.0-alpha24","2.1.0-alpha25","2.1.0-alpha26","2.1.0-alpha3","2.1.0-alpha4","2.1.0-alpha5","2.1.0-alpha6","2.1.0-alpha7","2.1.0-alpha8","2.1.0-alpha9","2.1.1","2.1.2","2.10.0","2.10.1","2.10.2","2.10.3","2.10.4","2.10.5","2.11.0","2.12.0","2.12.1","2.12.2","2.12.3","2.12.4","2.14.5","2.15.0","2.16.0","2.2.0","2.2.1","2.3.0","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.4.7","2.4.8","2.4.9","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.6.0","2.7.0","2.8.0","2.8.1","2.9.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.16.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-f9m8-cv68-674w/GHSA-f9m8-cv68-674w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N"}]}