Hi Chris, On Thu, Aug 06, 2026 at 09:56:13AM -0700, Chris Lamb wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA256 > > - ------------------------------------------------------------------------- > Debian LTS Advisory DLA-4721-1 [email protected] > https://www.debian.org/lts/security/ Chris Lamb > August 06, 2026 https://wiki.debian.org/LTS > - ------------------------------------------------------------------------- > > Package : async-http-client > Version : 2.12.2-1+deb11u1 > CVE ID : CVE-2026-55688 > Debian Bug : 1141445 > > It was discovered that there was a potential cookie injection > vulnerability in async-http-client, Java library used to make > asynchronous HTTP requests. > > CVE-2026-55688 > > Prevent a potential cookie injection or cookie tossing > vulnerability. ThreadSafeCookieStore stored a cookie under the > value of its Domain attribute, without verifying that the > responding host is allowed to set a cookie for that domain, > therefore leading to cookie tossing/injection issues. > > For Debian 11 bullseye, this problem has been fixed in version > 2.12.2-1+deb11u1. > > For Debian 12 bookworm, this problem has been fixed in version > 2.12.3-1+deb12u1.
This one claims that bookworm-security was fixed with the given version, but TTBOMK there is no such upload, only the bullseye-security one got accepted: https://lists.debian.org/debian-lts-changes/2026/08/msg00020.html I do not see either an asssociated upload on suchon.d.o. Can you have a look? Regards, Salvatore
