AsyncHttpClient, Cookie Override Vulnerability, CVE-2026-107228 (High) -DC-Oct2026-2934

Listen to this Post

The AsyncHttpClient (AHC) library contains an implementation flaw in its default-enabled cookie management store where explicitly provided request headers can be completely discarded. When a developer specifies a custom `Cookie` header via `setHeader` or addHeader, the client’s internal cookie store mechanism overwrites this header if any cookies exist for that target origin. This behavior acts as an incomplete remediation bypass of CVE-2024-53990, which previously targeted only cookies added through addCookie. Because headers set explicitly via request builders never interface with the internal cookie list during early processing, the automated store mechanism flushes them out and replaces them with cached domain cookies. In multi-user systems sharing a single client instance, this flaw results in severe cross-user session contamination, where one user’s outbound request inherits authentication tokens or sensitive data belonging to an entirely different user session.

DailyCVE Form:

Platform: AsyncHttpClient
Version: 3.0.14
Vulnerability : Cookie Override
Severity: High
date: 2024-12-02

Prediction: Already Patched

What Undercode Say:

Analytics

Bash Commands and Codes:

AsyncHttpClient client = Dsl.asyncHttpClient();
client.prepareGet("https://example.com/api")
.setHeader("Cookie", "session=user_token_123")
.execute();

Exploit: (Educational Purposes!)

// Exploiting shared client context cross-contamination
AsyncHttpClient sharedClient = Dsl.asyncHttpClient();
// User A response populates store, User B explicit header gets overwritten

Protection: from this CVE

AsyncHttpClientConfig config = Dsl.config().setCookieStore(null).build();
AsyncHttpClient client = Dsl.asyncHttpClient(config);

Impact:

Cross-user session hijacking, authentication bypass, unauthorized data access.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top