CVE Explorer
CVE-2026-55688
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and from 3.0.0.Beta1 prior to 3.0.11, ThreadSafeCookieStore stored a cookie under the value of its Domain attribute without verifying that the responding host is allowed to set a cookie for that domain, leading to a cookie tossing / cookie injection issue. A host the client connects to can therefore plant a cookie scoped to a
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"async-http-client","vendor":"AsyncHttpClient","versions":[{"status":"affected","version":">= 2.0.0, < 2.16.0"},{"status":"affected","version":">= 3.0.0.Beta1, < 3.0.11"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:0beba5fab8b08ed88c39ecbd2729df431eca6da6154609dc3e4eb11044307eea · sha256:503bb284e355b296… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:0beba5fab8b08ed88c39ecbd2729df431eca6da6154609dc3e4eb11044307eea · sha256:503bb284e355b296… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-1275","description":"CWE-1275: Sensitive Cookie with Improper SameSite Attribute","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0beba5fab8b08ed88c39ecbd2729df431eca6da6154609dc3e4eb11044307eea · sha256:503bb284e355b296… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/AsyncHttpClient/async-http-client/pull/2196","tags":["x_refsource_MISC"],"url":"https://github.com/AsyncHttpClient/async-http-client/pull/2196"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0beba5fab8b08ed88c39ecbd2729df431eca6da6154609dc3e4eb11044307eea · sha256:503bb284e355b296… · /containers/cna/references/1
{"name":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-m452-q8c9-rg2f","tags":["x_refsource_CONFIRM"],"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-m452-q8c9-rg2f"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0beba5fab8b08ed88c39ecbd2729df431eca6da6154609dc3e4eb11044307eea · sha256:503bb284e355b296… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.