-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4721-1                [email protected]
https://www.debian.org/lts/security/                           Chris Lamb
August 06, 2026                               https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : async-http-client
Version        : 2.12.2-1+deb11u1
CVE ID         : CVE-2026-55688
Debian Bug     : 1141445

It was discovered that there was a potential cookie injection
vulnerability in async-http-client, Java library used to make
asynchronous HTTP requests.

CVE-2026-55688

    Prevent a potential cookie injection or cookie tossing
    vulnerability. ThreadSafeCookieStore stored a cookie under the
    value of its Domain attribute, without verifying that the
    responding host is allowed to set a cookie for that domain,
    therefore leading to cookie tossing/injection issues.

For Debian 11 bullseye, this problem has been fixed in version
2.12.2-1+deb11u1.

For Debian 12 bookworm, this problem has been fixed in version
2.12.3-1+deb12u1.

We recommend that you upgrade your async-http-client packages.

For the detailed security status of async-http-client please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/async-http-client

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmp0rjAACgkQHpU+J9Qx
HlhXHw//d6Lo6FbY2cpDc6KNRX7LRcQMVr6jHxIYB3Rv9Z6nPImb+Ak/W9twUzkT
zNQmTWCnU59683Ufl8knhD0+cJhTo1jVjdp1npR89rJChrA3NxWS3/Uif8lXK5nz
ofuYyax66DNjNk/N3HRcSwgcphz3+MPYjuv44/Cb+S0DJ311mNAg1Jz5JAgVKvyt
j8x17h2y/9RgFyMExN9avIXFTr+2wIxqSAm3/kfPy8xWevENgxvwII7DNfOICADf
l1YNUQPVAdn7p0yvPcmizjltEm3ulJYtAYv8phH3kb6jOOcfqRgM9fbH2Nhe3aaW
YURGlHAPLxcA0AZsVBAn3Ff/bQCLO3JdDgD1p+YboBMxpkY/zBgdupMqXiTn9vH/
OHPqPCOrUq/pKZJ+oHQ/CRYZmnwcUB8yScdXI4Rv1uiXj41ewijoj9rrH3nrc0Dp
hjbDLg3/qYWWNTPSGXlIDvbhKoRq8xYyWgCFiKQCC672d86mZwYNUvqdQaixY2eH
Z4FvJg9tMWnJ5ieE1Yi6JclJ+Kv87v+JnjBn94P5GDrnj/s29QFahkfS/Agmj2f5
DcsFWUm6gneodl7UsoF4F9jZL6douzr6fnvBOFMumJPgF5BvkzbbzMcOyFnvgZlu
e8q8lH9mKFdNOdY3K+crzJnvjme9/3ZDCXids1GfQOSDP4UgzF8=
=RTZe
-----END PGP SIGNATURE-----

Reply via email to