๐Ÿ” CVE Alert

CVE-2026-100724

MEDIUM 5.4

http4k before 6.49.0.0 Host Header Routing Bypass via reverseProxy

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses substring (Contains) matching on the Host header by default in reverseProxy() and reverseProxyRouting() when dispatching to configured virtual hosts. If these functions are deployed as a public-facing inbound HTTP handler with two or more configured virtual hosts, a remote attacker can supply a Host header that merely contains a configured vhost name (for example Host: admin.evil.com for a vhost configured as "admin") and be routed to that vhost, bypassing routing-based authorization. The intended outbound-dispatch and test-time uses, where the Host value is set by the calling application, are not affected.

CWE CWE-444
Vendor http4k
Product http4k
Published Sep 27, 2026
Stay Ahead of the Next One

Get instant alerts for http4k http4k

Be the first to know when new medium vulnerabilities affecting http4k http4k are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

http4k / http4k
0 < 6.49.0.0
http4k / http4k
0 < 5.42.0.0
http4k / http4k
0 < 4.51.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/http4k/http4k/security/advisories/GHSA-jrpc-7vxp-69p6 github.com: https://github.com/http4k/http4k/commit/0121b05537 github.com: https://github.com/http4k/http4k/commit/54c6385615 vulncheck.com: https://www.vulncheck.com/advisories/http4k-before-6.49.0.0-host-header-routing-bypass-via-reverseproxy