The problem is in REST-assured: https://github.com/rest-assured/rest-assured/issues/911. We may be less constrained and accept also situations with multiple cookie headers. But we should give at least a warning the HTTP request is invalid.