CVE-2026-107229 | async-http-client up to 2.16.1/3.0.13 ThreadSafeCookieStore session fixiation
A vulnerability was found in async-http-client up to 2.16.1/3.0.13. It has been rated as problematic. This issue affects some unknown processing of the component ThreadSafeCookieStore. This manipulation causes session fixiation.
This vulnerability is tracked as CVE-2026-107229. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More