{"id":"GHSA-fmxf-pm6p-7xgm","summary":"async-http-client: Cookie header not stripped on cross-origin redirect","details":"## Summary\n\nasync-http-client leaks `Cookie` headers to cross-origin redirect targets. When following a redirect across a security boundary (different origin, or HTTPS→HTTP downgrade), the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip `Cookie`, so session cookies and other sensitive cookie values are forwarded to the redirect target — which may be attacker-controlled.\n\n## Details\n\nThe vulnerability is in `client/src/main/java/org/asynchttpclient/netty/handler/intercept/Redirect30xInterceptor.java`.\n\nThe caller computes `stripAuth` on each redirect:\n\n```java\nboolean sameBase    = request.getUri().isSameBase(newUri);\nboolean stripAuth   = !sameBase || schemeDowngrade || stripAuthorizationOnRedirect;\n// ...\nrequestBuilder.setHeaders(propagatedHeaders(request, realm, keepBody, stripAuth));\n```\n\n`stripAuth` is `true` whenever the redirect crosses an origin, downgrades the scheme, or the caller opted in via `AsyncHttpClientConfig#isStripAuthorizationOnRedirect()`.\n\nIn the vulnerable version, `propagatedHeaders()` only removes `Authorization` and `Proxy-Authorization` in that branch — `Cookie` is left untouched:\n\n```java\nprivate static HttpHeaders propagatedHeaders(Request request, Realm realm, boolean keepBody, boolean stripAuthorization) {\n    HttpHeaders headers = request.getHeaders()\n            .remove(HOST)\n            .remove(CONTENT_LENGTH);\n\n    if (!keepBody) {\n        headers.remove(CONTENT_TYPE);\n    }\n\n    if (stripAuthorization || (realm != null && (realm.getScheme() == AuthScheme.NTLM\n            || realm.getScheme() == AuthScheme.SCRAM_SHA_256))) {\n        headers.remove(AUTHORIZATION)\n                .remove(PROXY_AUTHORIZATION);\n        // BUG: COOKIE is not removed here, so cookies leak across the security boundary.\n    }\n    return headers;\n}\n```\n\nThe companion test class `RedirectCredentialSecurityTest` covers `Authorization` / `Proxy-Authorization` stripping on cross-origin redirects and scheme downgrades, but has no coverage for `Cookie`, which is why the regression went unnoticed.\n\n## Proof of concept\n\n```java\nimport org.asynchttpclient.*;\n\nAsyncHttpClient client = asyncHttpClient();\n\n// trusted-api.com responds 302 -\u003e https://evil.com\nRequest request = new RequestBuilder(\"GET\")\n        .setUrl(\"https://trusted-api.com/endpoint\")\n        .setHeader(\"Cookie\", \"session=abc123; csrf=xyz789; api_key=secret\")\n        .setHeader(\"Authorization\", \"Bearer token123\")\n        .build();\n\nclient.executeRequest(request).get();\n\n// Request seen by evil.com after the redirect:\n//   Authorization: \u003cstripped\u003e\n//   Cookie:        session=abc123; csrf=xyz789; api_key=secret   \u003c-- leaked\n```\n\n## Impact\n\n- **Session hijacking** — leaked session cookies allow impersonation.\n- **CSRF token theft** — CSRF tokens carried in cookies are disclosed.\n- **API key theft** — API keys stored in cookies are disclosed.\n- **Privacy** — tracking identifiers leak to third-party origins.\n\nRealistic attack paths:\n\n- Open-redirect in a trusted API endpoint.\n- Compromised CDN or API gateway injecting redirects.\n- MITM on a plaintext hop in the redirect chain.\n\n## Fix\n\nAdd `COOKIE` to the headers removed alongside `AUTHORIZATION` / `PROXY_AUTHORIZATION` on the security-boundary branch:\n\n```java\nif (stripAuthorization) {\n    headers.remove(AUTHORIZATION)\n            .remove(PROXY_AUTHORIZATION)\n            .remove(COOKIE);\n} else if (realm != null && (realm.getScheme() == AuthScheme.NTLM\n        || realm.getScheme() == AuthScheme.SCRAM_SHA_256)) {\n    headers.remove(AUTHORIZATION)\n            .remove(PROXY_AUTHORIZATION);\n}\n```\n\nNote that the URI-scoped `CookieStore` will re-add any cookies that legitimately match the new target after `propagatedHeaders` returns, so legitimate cross-origin sessions tracked by the client are not broken.\n\nFixed in **3.0.10** and **2.15.0** by commit [`3b0e3e9e`](https://github.com/AsyncHttpClient/async-http-client/commit/3b0e3e9e).","aliases":["CVE-2026-45300"],"modified":"2026-07-17T21:13:37.367184889Z","published":"2026-05-18T16:42:20Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-18T16:42:20Z","nvd_published_at":"2026-06-05T20:17:31Z","cwe_ids":["CWE-200"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-fmxf-pm6p-7xgm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45300"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/commit/3b0e3e9e"},{"type":"PACKAGE","url":"https://github.com/AsyncHttpClient/async-http-client"},{"type":"WEB","url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.10"}],"affected":[{"package":{"name":"org.asynchttpclient:async-http-client","ecosystem":"Maven","purl":"pkg:maven/org.asynchttpclient/async-http-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0.Beta1"},{"fixed":"3.0.10"}]}],"versions":["3.0.0","3.0.0.Beta1","3.0.0.Beta2","3.0.0.Beta3","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fmxf-pm6p-7xgm/GHSA-fmxf-pm6p-7xgm.json"}},{"package":{"name":"org.asynchttpclient:async-http-client","ecosystem":"Maven","purl":"pkg:maven/org.asynchttpclient/async-http-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.15.0"}]}],"versions":["2.0.0","2.0.1","2.0.10","2.0.11","2.0.12","2.0.13","2.0.14","2.0.15","2.0.16","2.0.17","2.0.18","2.0.19","2.0.2","2.0.20","2.0.21","2.0.22","2.0.23","2.0.24","2.0.25","2.0.26","2.0.27","2.0.28","2.0.29","2.0.3","2.0.30","2.0.31","2.0.32","2.0.33","2.0.34","2.0.35","2.0.36","2.0.37","2.0.38","2.0.39","2.0.4","2.0.40","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.1.0","2.1.0-RC1","2.1.0-RC2","2.1.0-RC3","2.1.0-RC4","2.1.0-alpha1","2.1.0-alpha10","2.1.0-alpha11","2.1.0-alpha12","2.1.0-alpha13","2.1.0-alpha14","2.1.0-alpha15","2.1.0-alpha16","2.1.0-alpha17","2.1.0-alpha18","2.1.0-alpha19","2.1.0-alpha2","2.1.0-alpha20","2.1.0-alpha21","2.1.0-alpha22","2.1.0-alpha23","2.1.0-alpha24","2.1.0-alpha25","2.1.0-alpha26","2.1.0-alpha3","2.1.0-alpha4","2.1.0-alpha5","2.1.0-alpha6","2.1.0-alpha7","2.1.0-alpha8","2.1.0-alpha9","2.1.1","2.1.2","2.10.0","2.10.1","2.10.2","2.10.3","2.10.4","2.10.5","2.11.0","2.12.0","2.12.1","2.12.2","2.12.3","2.12.4","2.14.5","2.2.0","2.2.1","2.3.0","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.4.7","2.4.8","2.4.9","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.6.0","2.7.0","2.8.0","2.8.1","2.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fmxf-pm6p-7xgm/GHSA-fmxf-pm6p-7xgm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"}]}