THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-m452-q8c9-rg2f (medium) — AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore

[GHSA] GHSA-m452-q8c9-rg2f (medium) — AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore

medgithub_advisoriesPublished 2026-08-26

GHSA-m452-q8c9-rg2f Severity: medium CVE: CVE-2026-55688

AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore

### Impact A **cookie tossing / cookie injection** issue (CWE-1275). `ThreadSafeCookieStore` stored a cookie under the value of its `Domain` attribute without verifying that the responding host is allowed to set a cookie for that domain (RFC 6

Indicators of compromise

Original source: https://github.com/advisories/GHSA-m452-q8c9-rg2f