-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4721-1 [email protected]
https://www.debian.org/lts/security/ Chris Lamb
August 06, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : async-http-client
Version : 2.12.2-1+deb11u1
CVE ID : CVE-2026-55688
Debian Bug : 1141445
It was discovered that there was a potential cookie injection
vulnerability in async-http-client, Java library used to make
asynchronous HTTP requests.
CVE-2026-55688
Prevent a potential cookie injection or cookie tossing
vulnerability. ThreadSafeCookieStore stored a cookie under the
value of its Domain attribute, without verifying that the
responding host is allowed to set a cookie for that domain,
therefore leading to cookie tossing/injection issues.
For Debian 11 bullseye, this problem has been fixed in version
2.12.2-1+deb11u1.
For Debian 12 bookworm, this problem has been fixed in version
2.12.3-1+deb12u1.
We recommend that you upgrade your async-http-client packages.
For the detailed security status of async-http-client please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/async-http-client
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmp0rjAACgkQHpU+J9Qx
HlhXHw//d6Lo6FbY2cpDc6KNRX7LRcQMVr6jHxIYB3Rv9Z6nPImb+Ak/W9twUzkT
zNQmTWCnU59683Ufl8knhD0+cJhTo1jVjdp1npR89rJChrA3NxWS3/Uif8lXK5nz
ofuYyax66DNjNk/N3HRcSwgcphz3+MPYjuv44/Cb+S0DJ311mNAg1Jz5JAgVKvyt
j8x17h2y/9RgFyMExN9avIXFTr+2wIxqSAm3/kfPy8xWevENgxvwII7DNfOICADf
l1YNUQPVAdn7p0yvPcmizjltEm3ulJYtAYv8phH3kb6jOOcfqRgM9fbH2Nhe3aaW
YURGlHAPLxcA0AZsVBAn3Ff/bQCLO3JdDgD1p+YboBMxpkY/zBgdupMqXiTn9vH/
OHPqPCOrUq/pKZJ+oHQ/CRYZmnwcUB8yScdXI4Rv1uiXj41ewijoj9rrH3nrc0Dp
hjbDLg3/qYWWNTPSGXlIDvbhKoRq8xYyWgCFiKQCC672d86mZwYNUvqdQaixY2eH
Z4FvJg9tMWnJ5ieE1Yi6JclJ+Kv87v+JnjBn94P5GDrnj/s29QFahkfS/Agmj2f5
DcsFWUm6gneodl7UsoF4F9jZL6douzr6fnvBOFMumJPgF5BvkzbbzMcOyFnvgZlu
e8q8lH9mKFdNOdY3K+crzJnvjme9/3ZDCXids1GfQOSDP4UgzF8=
=RTZe
-----END PGP SIGNATURE-----