{"id":"CVE-2026-55688","aliases":["GHSA-m452-q8c9-rg2f"],"url":"https://o3.security/vulnerability/CVE-2026-55688","summary":"AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStore","details":"### Impact\n A **cookie tossing / cookie injection** issue (CWE-1275). `ThreadSafeCookieStore` stored a cookie under the value of its `Domain` attribute without verifying that the responding host is allowed to set a cookie for that domain (RFC 6265 §5.3 step 6). A host the client connects to can therefore plant a cookie scoped to an unrelated domain, and the client will then send that cookie on later requests to that domain.\n\n### Who is Impacted\nApplications that use a single `AsyncHttpClient` instance - and thus the default, shared `CookieStore` - to reach **both** an attacker-influenced host and a trusted host. Typical exposure: crawlers, link-preview / webhook fetchers, SSRF-style \"fetch this URL\" features, multi-backend aggregators, or following redirects to an attacker-controlled host. The attacker can *write* a cookie the client presents to the victim host (session fixation, overwriting a session id / CSRF-token cookie); they cannot *read* the victim host's cookies. Applications that talk only to a fixed trusted backend, or that disable/scope the cookie store, are not exposed.\n\n### Patches\nFixed in 3.0.11 and 2.16.0\n\n### Workarounds\n- Disable the cookie store (setCookieStore(null)) when cookies are not needed; or\n- Use a separate AsyncHttpClient (separate cookie store) per trust domain so an attacker-influenced host and a trusted host never share a jar\n- Supply a custom CookieStore whose add(Uri, Cookie) rejects cookies whose Domain is not domain-matched by the request host.","published":"2026-07-01T19:40:12.004Z","modified":"2026-08-28T04:10:58.143466202Z","cvss":{"score":4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"},"epss":{"score":0.0033,"percentile":0.25467,"asOf":"2026-08-27"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.asynchttpclient:async-http-client","fixedVersion":"3.0.11"},{"ecosystem":"Maven","name":"org.asynchttpclient:async-http-client","fixedVersion":"2.16.0"}],"fix":{"url":"https://github.com/AsyncHttpClient/async-http-client/pull/2196","label":"AsyncHttpClient/async-http-client#2196"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/08/msg00011.html"},{"type":"ADVISORY","url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-m452-q8c9-rg2f"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55688.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55688"},{"type":"FIX","url":"https://github.com/AsyncHttpClient/async-http-client/pull/2196"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/pull/2199"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/commit/8e4069cf3c92abe099db5fb13378ac2fe9e1fd3b"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/commit/e6955c1e3951cf80e286981d064f6c926ce33f47"},{"type":"PACKAGE","url":"https://github.com/AsyncHttpClient/async-http-client"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.0"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.11"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T04:10:58.143466202Z"}}