Impact
The vulnerability lies in the http4k DigestAuthProvider.verify function, which ignored the algorithm configured by users and always applied a hardcoded MD5 hash for digest authentication. This undermines the intended security level for deployments that intended to use SHA‑256, making the digest responses susceptible to collision‑based attacks that rely on MD5’s lower collision resistance. The result is a reduction in authentication integrity and a potential path to authentication bypass if an attacker can craft a message that collides under MD5.
Affected Systems
The affected library is the http4k security digest component of the http4k toolkit, used in Kotlin HTTP applications. Versions prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0 are impacted. Users of these releases should verify that they are not running an older version before applying the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity impact. The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation, although the CWE‑327 weakness can be leveraged by an attacker who can interact with the authenticated service, such as a client that sends crafted digest credentials over the network. The likely attack vector is remote interaction with the service’s Digest authentication endpoint. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at the time of this analysis.
OpenCVE Enrichment
Github GHSA