Impact
The vulnerability lies in the DigestAuthProvider.verify function of the http4k API toolkit. The function fails to compare the URI supplied in an Authorization: Digest response with the actual request URL. Consequently, an attacker who captures a valid Digest authentication response can replay it against a different endpoint within the same realm, gaining unauthorized read or write access. This flaw represents a classic authorization bypass and is defined as CWE‑294, improper calculation of authorization data.
Affected Systems
The issue affects http4k HTTP application toolkit versions prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0. Any Kotlin HTTP application that uses http4k-security-digest in these releases is vulnerable. The fix is released in the corresponding patch versions.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity with an impact on confidentiality, integrity, and availability. EPSS indicates a < 1% likelihood of exploitation; however, the vulnerability still permits replay attacks that can be performed without special privileges. The vulnerability is not listed in the CISA KEV catalog. An attacker would need the ability to capture a valid Digest authentication response, then reuse it against a different endpoint served by the same realm. The attack likely occurs over the same network session or if captured credentials are replayed at any time.
OpenCVE Enrichment
Github GHSA