Description
http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response with hardcoded MD5. Deployments configured for SHA-256 therefore receive weaker MD5-based verification, exposing Digest authentication to collision-related attack paths that depend on the hash function's collision resistance. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass Through Weak Digest Algorithm
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in the http4k DigestAuthProvider.verify function, which ignored the algorithm configured by users and always applied a hardcoded MD5 hash for digest authentication. This undermines the intended security level for deployments that intended to use SHA‑256, making the digest responses susceptible to collision‑based attacks that rely on MD5’s lower collision resistance. The result is a reduction in authentication integrity and a potential path to authentication bypass if an attacker can craft a message that collides under MD5.

Affected Systems

The affected library is the http4k security digest component of the http4k toolkit, used in Kotlin HTTP applications. Versions prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0 are impacted. Users of these releases should verify that they are not running an older version before applying the fix.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity impact. The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation, although the CWE‑327 weakness can be leveraged by an attacker who can interact with the authenticated service, such as a client that sends crafted digest credentials over the network. The likely attack vector is remote interaction with the service’s Digest authentication endpoint. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at the time of this analysis.

Generated by OpenCVE AI on September 19, 2026 at 17:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade http4k to version 4.51.0.0, 5.42.0.0, or 6.50.0.0 or later where the DigestAuthProvider.verify function correctly honors the configured algorithm
  • If an immediate upgrade is not feasible, disable Digest authentication or switch to an alternative method (e.g., Basic auth, OAuth) until the vulnerability is patched
  • Apply network monitoring and rate limiting on endpoints that use Digest authentication to detect anomalous or repeated authentication attempts during the transition period

Generated by OpenCVE AI on September 19, 2026 at 17:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vxxm-wwqh-mh47 http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI
History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Http4k
Http4k http4k
Vendors & Products Http4k
Http4k http4k

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response with hardcoded MD5. Deployments configured for SHA-256 therefore receive weaker MD5-based verification, exposing Digest authentication to collision-related attack paths that depend on the hash function's collision resistance. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.
Title http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI
Weaknesses CWE-327
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T17:28:07.389Z

Reserved: 2026-06-11T21:15:33.871Z

Link: CVE-2026-54147

cve-icon Vulnrichment

Updated: 2026-09-18T17:27:57.352Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:06.677

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:28:51Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm