CVE-2026-107226 is a cookie-origin enforcement vulnerability in AsyncHttpClient affecting its cookie store and applications that use it, including affected Chainguard druid packages. The cookie store accepts cookies from plaintext HTTP responses that can plant, overwrite, or delete Secure cookies subsequently used in HTTPS requests. Cookie ordering can also give attacker-controlled plaintext cookies precedence over HTTPS-origin cookies. An attacker controlling a plaintext HTTP response can consequently influence cookies used by an HTTPS application, potentially enabling session fixation, CSRF-token replacement, or deletion of security-relevant cookies.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A medium-severity vulnerability affecting Chainguard's druid library and related packages. The advisory assigns a CVSS v3 score of 6.8; its vector indicates network-based exploitation with high attack complexity, no required privileges or user interaction, and high integrity impact. The underlying flaw is not described. Updating to version 38.0.0-r4 or later addresses the vulnerability.
AsyncHttpClient fails to enforce secure-context restrictions when storing cookies. An attacker able to answer a plaintext HTTP request, including through an untrusted same-site host, can plant, overwrite, or delete Secure cookies subsequently used by an HTTPS site. Application-dependent consequences include session fixation, CSRF-token replacement, and deletion of security-relevant cookies. Cookie ordering also permits plaintext cookies to take precedence over HTTPS cookies. Affected versions are 3.x through 3.0.13 and 2.x from 2.1.0 through 2.16.1. Version 3.0.14 fixes the issue; the end-of-life 2.x branch will not receive a fix. Workarounds include disabling the cookie store or avoiding shared cookie stores between mutually untrusted plaintext and HTTPS origins.
A medium-severity vulnerability affecting org.asynchttpclient:async-http-client. The listed CVSS v3 score is 6.8, indicating a network-accessible attack requiring high complexity, no privileges, and no user interaction, with high integrity impact. The content does not describe the underlying flaw or exploitation mechanism.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.