CVE-2026-107228 | async-http-client up to 3.0.13 Cookie Store setHeader session fixiation
A vulnerability, which was classified as critical, was found in async-http-client up to 3.0.13. The impacted element is the function setHeader of the component Cookie Store. The manipulation results in session fixiation.
This vulnerability was named CVE-2026-107228. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More