Description
http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the actual request URL. An attacker who captures a valid Digest authentication response can replay it against another URL served by the same realm, bypassing the per-request-URI binding and potentially gaining unauthorized read or write access. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.
Published: 2026-09-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in the DigestAuthProvider.verify function of the http4k API toolkit. The function fails to compare the URI supplied in an Authorization: Digest response with the actual request URL. Consequently, an attacker who captures a valid Digest authentication response can replay it against a different endpoint within the same realm, gaining unauthorized read or write access. This flaw represents a classic authorization bypass and is defined as CWE‑294, improper calculation of authorization data.

Affected Systems

The issue affects http4k HTTP application toolkit versions prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0. Any Kotlin HTTP application that uses http4k-security-digest in these releases is vulnerable. The fix is released in the corresponding patch versions.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity with an impact on confidentiality, integrity, and availability. EPSS indicates a < 1% likelihood of exploitation; however, the vulnerability still permits replay attacks that can be performed without special privileges. The vulnerability is not listed in the CISA KEV catalog. An attacker would need the ability to capture a valid Digest authentication response, then reuse it against a different endpoint served by the same realm. The attack likely occurs over the same network session or if captured credentials are replayed at any time.

Generated by OpenCVE AI on September 19, 2026 at 17:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update http4k to version 4.51.0.0, 5.42.0.0, or 6.50.0.0 or later to apply the official fix
  • If an update is not immediately possible, disable Digest authentication for the affected endpoints or enforce strict URI binding in custom handlers
  • Monitor authentication logs for repeated reuse of the same Authorization: Digest headers across multiple URIs

Generated by OpenCVE AI on September 19, 2026 at 17:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-p28p-j94q-pg32 http4k: `DigestAuthProvider.verify` did not bind to request URI
History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Http4k
Http4k http4k
Vendors & Products Http4k
Http4k http4k

Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the actual request URL. An attacker who captures a valid Digest authentication response can replay it against another URL served by the same realm, bypassing the per-request-URI binding and potentially gaining unauthorized read or write access. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.
Title http4k: `DigestAuthProvider.verify` did not bind to request URI
Weaknesses CWE-294
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T14:54:12.650Z

Reserved: 2026-06-11T21:15:33.871Z

Link: CVE-2026-54148

cve-icon Vulnrichment

Updated: 2026-09-22T14:54:08.005Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:06.823

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:28:55Z

Weaknesses
  • CWE-294

    Authentication Bypass by Capture-replay