CVE-2026-55688
ADVISORY - githubSummary
Impact
A cookie tossing / cookie injection issue (CWE-1275). ThreadSafeCookieStore stored a cookie under the value of its Domain attribute without verifying that the responding host is allowed to set a cookie for that domain (RFC 6265 §5.3 step 6). A host the client connects to can therefore plant a cookie scoped to an unrelated domain, and the client will then send that cookie on later requests to that domain.
Who is Impacted
Applications that use a single AsyncHttpClient instance - and thus the default, shared CookieStore - to reach both an attacker-influenced host and a trusted host. Typical exposure: crawlers, link-preview / webhook fetchers, SSRF-style "fetch this URL" features, multi-backend aggregators, or following redirects to an attacker-controlled host. The attacker can write a cookie the client presents to the victim host (session fixation, overwriting a session id / CSRF-token cookie); they cannot read the victim host's cookies. Applications that talk only to a fixed trusted backend, or that disable/scope the cookie store, are not exposed.
Patches
Fixed in 3.0.11 and 2.16.0
Workarounds
- Disable the cookie store (setCookieStore(null)) when cookies are not needed; or
- Use a separate AsyncHttpClient (separate cookie store) per trust domain so an attacker-influenced host and a trusted host never share a jar
- Supply a custom CookieStore whose add(Uri, Cookie) rejects cookies whose Domain is not domain-matched by the request host.
Common Weakness Enumeration (CWE)
Sensitive Cookie with Improper SameSite Attribute
Sensitive Cookie with Improper SameSite Attribute
NIST
2.2
CVSS SCORE
4mediumGitHub
2.2
CVSS SCORE
4mediumDebian
-
Ubuntu
-