๐Ÿ” CVE Alert

CVE-2026-100725

MEDIUM 6.5

http4k before 6.48.0.0 Cookie Scoping Bypass via BasicCookieStorage

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (client-side cookie store used by ClientFilters.Cookies) that does not enforce RFC 6265 scoping rules for the cookie domain, path, and Secure attributes. When a single BasicCookieStorage instance is used to talk to more than one origin or scheme, cookies stored for one origin can be sent to other origins, and cookies marked Secure can be sent over plain HTTP, potentially disclosing session cookies or other sensitive values to unauthorized hosts or network observers. Clients that use a storage instance for a single origin are not affected.

CWE CWE-200
Vendor http4k
Product http4k
Published Sep 27, 2026
Stay Ahead of the Next One

Get instant alerts for http4k http4k

Be the first to know when new medium vulnerabilities affecting http4k http4k are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

http4k / http4k
0 < 6.48.0.0
http4k / http4k
0 < 5.42.0.0
http4k / http4k
0 < 4.51.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/http4k/http4k/security/advisories/GHSA-pr33-38xx-6r26 github.com: https://github.com/http4k/http4k/commit/6a9b44d743 vulncheck.com: https://www.vulncheck.com/advisories/http4k-before-6.48.0.0-cookie-scoping-bypass-via-basiccookiestorage