Protection mechanism failure in Async-http-client - #VU152426
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to plant, overwrite, or delete secure cookies.
The vulnerability exists due to improper enforcement of secure cookie protections in ThreadSafeCookieStore when handling Set-Cookie headers received over plaintext HTTP. A remote attacker can respond to a plaintext request with a crafted Set-Cookie header to plant, overwrite, or delete secure cookies.