Session Fixation in Async-http-client - #VU152424
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject cookies into requests to other hosts.
The vulnerability exists due to incomplete origin checks in the default ThreadSafeCookieStore when processing Set-Cookie headers with Domain attributes from attacker-influenced origins. A remote attacker can cause a cookie to be stored under a key matched by a later request to a different host to inject cookies into requests to other hosts.
Exploitation requires a single AsyncHttpClient instance with its default cookie store enabled to access multiple origins, including an attacker-influenced origin.