Protection Mechanism Failure Affecting org.asynchttpclient:async-http-client package, versions [2.1.0,3.0.14)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGASYNCHTTPCLIENT-20574185
  • published8 Oct 2026
  • disclosed8 Oct 2026
  • creditUnknown

Introduced: 8 Oct 2026

NewCVE-2026-107226  (opens in a new tab)
CWE-384  (opens in a new tab)
CWE-693  (opens in a new tab)

How to fix?

Upgrade org.asynchttpclient:async-http-client to version 3.0.14 or higher.

Overview

org.asynchttpclient:async-http-client is a maven plugin for the Async Http Client (AHC) classes.

Affected versions of this package are vulnerable to Protection Mechanism Failure due to improper handling of the scheme when processing Set-Cookie headers. An attacker can overwrite, plant, or delete secure cookies by sending crafted HTTP responses over plaintext connections, which can result in session fixation, CSRF token manipulation, or removal of critical cookies. This is only exploitable if a plaintext host under the same site is able to set cookies for the target domain.

Workaround

This vulnerability can be mitigated by not sharing one CookieStore between plaintext and HTTPS origins that are not mutually trusted, or by disabling the cookie store.

CVSS Base Scores

version 4.0
version 3.1