CVE-2026-107280
Publication date 8 October 2026
Last updated 8 October 2026
Ubuntu priority
Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, ThreadSafeCookieStore validates Domain attributes with domain matching but does not reject public suffixes. A host beneath a suffix such as co.uk can set a cookie for that suffix, after which the shared cookie store sends it to unrelated hosts under the suffix. This can inject or overwrite session-relevant cookie values across origins. This issue is fixed in versions 3.0.13 and 2.16.1.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| async-http-client | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
Severity score breakdown
CVSS version: CVSS v4.0
Base score
6.9 · Medium
Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-107280
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f9m8-cv68-674w
- https://github.com/AsyncHttpClient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f (async-http-client-project-2.16.1)
- https://github.com/AsyncHttpClient/async-http-client/commit/330267895fe0bdb41bbd027ea6b151d38ee7c23d
- https://github.com/AsyncHttpClient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f
- https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1
- https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13