Improper Authentication in Async-http-client - #VU152427
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to access and act under another user's session.
The vulnerability exists due to improper authentication in CookieStore handling of Cookie headers when an application shares a client and its cookie store among users while setting session cookies with setHeader or addHeader. A remote user can cause a request to be sent with a cookie from another user's session to access or act under another user's session.
The cookie store is enabled by default.