AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-107226.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 08, 2026

Disclosure summary

### Impact The cookie store ignores the scheme a `Set-Cookie` arrived on. draft-ietf-httpbis-rfc6265bis-22 (approved to obsolete RFC 6265, in the RFC Editor queue) Section 5.7 requires a user agent to ignore a cookie with the `Secure` attribute unless it arrived over a secure connection (step 13), and to ignore a non-Secure cookie from an insecure connection when it would overlay a Secure cookie the store already holds (step 16). Neither rule is implemented. The only `Secure` handling is on retrieval, where a Secure cookie is not sent over plaintext. So anyone who can answer a plaintext request to a site can set, replace or delete the site's `Secure` cookies, and the next HTTPS request carries the attacker's value back inside TLS: ``` http://example.com -> Set-Cookie: SID=attacker-value; Secure; Path=/ https://example.com -> Cookie: SID=attacker-value ``` This does not need an attacker on the network path. A plaintext host under the same site reaches the HTTPS one by setting a domain cookie: ``` http://insecure.example.com -> Set-Cookie: SID=attacker-value; Secure; Domain=example.com; Path=/ https://bank.example.com -> Cookie: SID=attacker-value ``` A plaintext `Set-Cookie` of the

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-p2jm-6hj6-9rjg

Open original source · Updated Oct 08, 2026

AsyncHttpClient: Cookies received over plaintext HTTP can plant, overwrite or delete Secure cookies set over HTTPS

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
mavenorg.asynchttpclient:async-http-client>= 3.0.0,3.0.14
mavenorg.asynchttpclient:async-http-client>= 2.1.0,Not supplied

Original records & references

PUBLISHED 2026-10-08T12:49:59-04:00
MODIFIED 2026-10-08T12:50:00-04:00
INGESTED 2026-10-10T20:25:13-04:00