AsyncHttpClient, Cookie Handling Flaw, CVE-2026-107229 (Critical) -DC-Oct2026-2931

Listen to this Post

The AsyncHttpClient library features a critical vulnerability in its cookie store implementation where the underlying architecture completely ignores the scheme over which a Set-Cookie response arrives. Modern specifications like RFC 6265bis mandate that user agents must ignore cookies marked with the Secure attribute unless they are received over a secure connection, and must similarly reject unsecured cookies attempting to overlay existing Secure cookies from insecure channels. Because the ThreadSafeCookieStore component fails to enforce these rules during storage and reduces incoming URIs solely to hosts and paths, any entity capable of answering plaintext HTTP requests for a site can plant, overwrite, or delete Secure cookies. Consequently, subsequent requests sent over secure HTTPS transport automatically carry attacker-controlled cookie values inside the TLS layer. This behavior leads directly to severe consequences such as session fixation, corrupted CSRF tokens, or complete removal of critical application cookies without requiring an attacker to occupy an active network path position.

DailyCVE Form:

Platform: AsyncHttpClient
Version: 3.x-and-2.x
Vulnerability : Cookie-Tossing
Severity: Critical
date: 2026-10-07

Prediction: 2026-10-07

What Undercode Say

Analytics

The vulnerability stems from design flaws in ThreadSafeCookieStore.add(Uri, Cookie), which extracts only the host and path components before evaluating storage criteria, stripping out the protocol scheme entirely. Because the scheme context is lost early, validation checks fail to determine whether a cookie originated from an insecure transport layer. Furthermore, hash-ordered returns combined with non-restrictive path matching allow malicious plaintext responses to position injected cookies ahead of legitimate ones, forcing clients to pick attacker parameters during request builder execution.

Bash Commands and Codes Related to the Blog

// Vulnerable storage snippet reducing URI context
public void add(Uri uri, Cookie cookie) {
String host = uri.getHost();
String path = uri.getPath();
// Scheme is completely discarded here, allowing insecure Set-Cookie to override Secure cookies
doStore(host, path, cookie);
}
Simulating an insecure cookie injection vector via curl targeting plaintext endpoints
curl -i "http://example.com/endpoint" \
--header "Host: example.com"
Response contains: Set-Cookie: SID=attacker-value; Secure; Path=/

Exploit: (Educational Purposes!)

An attacker exploits this vulnerability by interacting with the cleartext HTTP service hosted under the target domain infrastructure. By sending a malicious response containing an artificially crafted `Set-Cookie` header with the `Secure` flag or matching path attributes, the attacker overwrites high-privilege session identifiers or CSRF tokens. When the victim browser or application executes subsequent requests over `https://`, the injected values are transmitted directly inside the encrypted tunnel, resulting in unauthorized session fixation or compromise.

Protection: From This CVE

To mitigate this vulnerability, administrators and developers must immediately upgrade the AsyncHttpClient library to version 3.0.14 or later, where strict scheme verification and ordered context retrieval are enforced. If upgrading is immediately unfeasible, avoid sharing a single client cookie store across mutually untrusted plaintext and HTTPS origins, or disable the cookie store entirely when persistent session management across mixed environments is not strictly required.

Impact:

The impact includes high integrity degradation, allowing remote attackers to arbitrarily overwrite, plant, or delete Secure cookies across shared application boundaries. Because the corruption affects secure HTTPS sessions originating from plaintext vectors, successful exploitation leads to session hijacking, persistent session fixation, and complete bypass of transport-layer cookie protections.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top