CVE-2026-107280 | AsyncHttpClient async-http-client up to 2.16.0/3.0.12 ThreadSafeCookieStore cross-domain policy

SecurityVulns

A vulnerability described as problematic has been identified in AsyncHttpClient async-http-client up to 2.16.0/3.0.12. This impacts an unknown function of the component ThreadSafeCookieStore. The manipulation results in permissive cross-domain policy with untrusted domains.

This vulnerability is reported as CVE-2026-107280. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More