Listen to this Post
The AsyncHttpClient library relies on the ThreadSafeCookieStore component to manage and store HTTP cookies during network requests.
The vulnerability arises because the cookie store determines whether a Domain attribute can be accepted using exclusively the domain-matching rule specified in RFC 6265 Section 5.1.3.
This rule checks only whether the request host is equal to the domain or ends with a dot followed by the domain string.
Crucially, Section 5.3 step 5 of the RFC, which mandates the rejection of a Domain value that corresponds to a public suffix, is completely missing from the client implementation.
Consequently, a malicious host operating under a multi-label public suffix can successfully set a cookie for the suffix itself.
Once stored, the client’s cookie store hands this injected cookie to every other host falling under that same public suffix.
For example, an attacker on attacker.co.uk can issue a Set-Cookie header with Domain=co.uk, which is then sent to bank.co.uk.
Suffixes such as co.uk, com.au, or github.io make acquiring such a site trivially obtainable for malicious actors.
Depending on the application logic, this vulnerability manifests as session fixation, overwrites existing session cookies, or plants untrusted data.
While CVE-2026-55688 addressed direct domain-naming attacks where an unrelated domain is named directly, the residual vulnerability regarding public suffixes remained unpatched in versions 3.x up to 3.0.12 and 2.x up to 2.16.0.
DailyCVE Form:
Platform: AsyncHttpClient
Version: 3.x and 2.x
Vulnerability : Cookie injection flaw
Severity: Medium severity level
date: June 2026
Prediction: Patched in 3.0.13
What Undercode Say:
Check vulnerable async-http-client dependency version mvn dependency:tree | grep async-http-client Inspect ThreadSafeCookieStore domainsMatch implementation javap -c org.asynchttpclient.cookie.ThreadSafeCookieStore
// Vulnerable logic snippet
public boolean domainsMatch(String requestDomain, String cookieDomain) {
return requestDomain.equals(cookieDomain) || requestDomain.endsWith('.' + cookieDomain);
}
Exploit: (Educational Purposes!)
An attacker deploys a server under a multi-label public suffix like attacker.co.uk. When a victim application connects to this server using a shared AsyncHttpClient instance, the server responds with an HTTP header:
Set-Cookie: SID=attacker-value; Domain=co.uk; Path=/
Because the client lacks a public suffix check, it accepts the cookie for the entire .co.uk suffix. Subsequently, when the same client instance makes a request to bank.co.uk, it automatically attaches the attacker’s crafted cookie:
Cookie: SID=attacker-value
This results in session hijacking, session overwriting, or injecting malicious trust states into the victim application.
Protection: from this CVE
To protect against this vulnerability, users must upgrade the AsyncHttpClient library to version 3.0.13 or higher on the 3.x line, which integrates the Mozilla public suffix list to automatically reject cookies whose domains match ICANN public suffixes. If upgrading is not immediately possible, workarounds include avoiding the sharing of a single CookieStore instance across untrusted origins or supplying a custom CookieStore implementation that explicitly validates and rejects public suffix domain values.
Impact
The impact of this vulnerability involves unauthorized cookie injection across sibling domains sharing a public suffix. Depending on how target web applications process cookies, it can lead to severe security consequences including session fixation attacks, overwriting legitimate user sessions, or planting untrusted values that applications mistakenly trust, thereby compromising user session integrity and application security.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

