Vulnerability GHSA-f9m8-cv68-674w

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
6 hours ago
October 08, 2026 at 04:30 PM UTC
AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so a cookie can be set for co.uk
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.0
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.0

Summary

AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, so a cookie can be set for co.uk

Details

Impact

The cookie store decides whether a Domain attribute may be accepted using only the domain-matching rule of RFC 6265 Section 5.1.3, which asks whether the request host is the domain or ends with a dot followed by it. Section 5.3 step 5, which additionally requires rejecting a Domain that is a public suffix, is not implemented anywhere in the client.

So a host under a multi-label public suffix can set a cookie for the suffix itself, and the store then hands it to every other host under that suffix:

attacker.co.uk  ->  Set-Cookie: SID=attacker-value; Domain=co.uk; Path=/
bank.co.uk      ->  Cookie: SID=attacker-value

Domain=uk works the same way. The attacker needs only a site under the same suffix as the victim, which for suffixes such as co.uk, com.au, or github.io is trivially obtainable.

Depending on what the application does with the cookie, this is session fixation, or it overwrites a session the victim site set, or it lets the attacker plant a value the victim site trusts.

Affected versions

  • 3.x: up to and including 3.0.12
  • 2.x: up to and including 2.16.0

Relationship to CVE-2026-55688

CVE-2026-55688 (GHSA-m452-q8c9-rg2f) covered the direct form of this, where a host sets a Domain naming an unrelated host, and that form is genuinely fixed: attacker.co.uk can no longer set Domain=bank.co.uk, and this was verified as a control. What that fix did not add is the public suffix test, so setting Domain=co.uk still reaches bank.co.uk. This advisory covers only the residual.

Patches

Fixed in 3.0.13 on the 3.x line. The ICANN section of the Mozilla public suffix list is bundled with the client and a Domain matching it is rejected, honouring the list's wildcard and exception rules. The list is data and goes stale, so a suffix added upstream after a release is not recognised until the bundled copy is refreshed. The 2.x line is not yet fixed.

Workarounds

Do not share one CookieStore across origins that are not mutually trusted. Supplying a CookieStore implementation that rejects Domain values which are public suffixes also avoids it.

Details

ThreadSafeCookieStore.domainsMatch is requestDomain.equals(cookieDomain) || requestDomain.endsWith('.' + cookieDomain). It is used both to accept a Domain on storage and to select cookies for a request, and neither call site consults a public suffix list. A search of the client for any public suffix or effective TLD handling returns nothing.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Medium Risk
6 hours ago
AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Header via setHeader (Bypass of CVE-2024-53990 Fix)
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-2jwh-9rmr-j4xf
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-2jwh-9rmr-j4xf
Medium Risk
6 hours ago
AsyncHttpClient: Cookies received over plaintext HTTP can plant, overwrite or delete Secure cookies set over HTTPS
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-p2jm-6hj6-9rjg
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-p2jm-6hj6-9rjg
High Risk
6 hours ago
AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables a decompression-bomb denial of service when compression is enabled
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-x8v2-478q-2hvg
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-x8v2-478q-2hvg
High Risk
6 hours ago
AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-v2j5-22fr-j62r
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.1 GHSA-v2j5-22fr-j62r
Low Risk
6 hours ago
AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random source
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.0 GHSA-mfj3-87qq-382v
2.2.0 - 2.3.0 and 2.6.0 - 2.9.0 and 2.11.0 and 2.14.5 - 2.16.0 GHSA-mfj3-87qq-382v
View all vulnerabilities for these packages

Timeline

Published
6 hours ago
October 08, 2026 at 04:30 PM UTC
Fixed (3.0.13)
Unknown
Unknown
Fixed (2.16.1)
Unknown
Unknown
Last Modified
6 hours ago
October 08, 2026 at 04:45 PM UTC