Hi Chris,

On Thu, Aug 06, 2026 at 09:56:13AM -0700, Chris Lamb wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA256
> 
> - -------------------------------------------------------------------------
> Debian LTS Advisory DLA-4721-1                [email protected]
> https://www.debian.org/lts/security/                           Chris Lamb
> August 06, 2026                               https://wiki.debian.org/LTS
> - -------------------------------------------------------------------------
> 
> Package        : async-http-client
> Version        : 2.12.2-1+deb11u1
> CVE ID         : CVE-2026-55688
> Debian Bug     : 1141445
> 
> It was discovered that there was a potential cookie injection
> vulnerability in async-http-client, Java library used to make
> asynchronous HTTP requests.
> 
> CVE-2026-55688
> 
>     Prevent a potential cookie injection or cookie tossing
>     vulnerability. ThreadSafeCookieStore stored a cookie under the
>     value of its Domain attribute, without verifying that the
>     responding host is allowed to set a cookie for that domain,
>     therefore leading to cookie tossing/injection issues.
> 
> For Debian 11 bullseye, this problem has been fixed in version
> 2.12.2-1+deb11u1.
> 
> For Debian 12 bookworm, this problem has been fixed in version
> 2.12.3-1+deb12u1.

This one claims that bookworm-security was fixed with the given
version, but TTBOMK there is no such upload, only the
bullseye-security one got accepted:

https://lists.debian.org/debian-lts-changes/2026/08/msg00020.html

I do not see either an asssociated upload on suchon.d.o.

Can you have a look?

Regards,
Salvatore

Reply via email to