๐Ÿ” CVE Alert

CVE-2026-54147

MEDIUM 6.5

http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response with hardcoded MD5. Deployments configured for SHA-256 therefore receive weaker MD5-based verification, exposing Digest authentication to collision-related attack paths that depend on the hash function's collision resistance. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.

CWE CWE-327
Vendor http4k
Product http4k
Published Sep 18, 2026
Last Updated Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for http4k http4k

Be the first to know when new medium vulnerabilities affecting http4k http4k are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None

Affected Versions

http4k / http4k
< 4.51.0.0 >= 5.0.0.0, < 5.42.0.0 >= 6.0.0.0, < 6.50.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/http4k/http4k/security/advisories/GHSA-vxxm-wwqh-mh47 github.com: https://github.com/http4k/http4k/commit/65d23d99fc5afbe34f29d8f61d0a003fbebb381c github.com: https://github.com/http4k/http4k/releases/tag/6.50.0.0