๐Ÿ” CVE Alert

CVE-2026-54148

HIGH 8.1

http4k: `DigestAuthProvider.verify` did not bind to request URI

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the actual request URL. An attacker who captures a valid Digest authentication response can replay it against another URL served by the same realm, bypassing the per-request-URI binding and potentially gaining unauthorized read or write access. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.

CWE CWE-294
Vendor http4k
Product http4k
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for http4k http4k

Be the first to know when new high vulnerabilities affecting http4k http4k are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

http4k / http4k
< 4.51.0.0 >= 5.0.0.0, < 5.42.0.0 >= 6.0.0.0, < 6.50.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/http4k/http4k/security/advisories/GHSA-p28p-j94q-pg32 github.com: https://github.com/github/advisory-database/pull/9477 github.com: https://github.com/http4k/http4k/commit/725f1b96978dd433348e2b149c1e72b9f5147c90 github.com: https://github.com/http4k/http4k/releases/tag/6.50.0.0