HIGH 8.1 GitHub

CVE-2026-54148

http4k: `DigestAuthProvider.verify` did not bind to request URI

### Impact An issue in `DigestAuthProvider.verify`: The `uri` parameter in the client's `Authorization: Digest …` response was not checked against the actual request URL. A captured Digest authentication response could be replayed against any other URL served by the same realm, breaking the per-request-URL binding the Digest scheme assumes. **Who is affected:** any application using `http4k-security-digest` for HTTP Digest authentication. The bug has been present since `DigestAuthProvider` wa

Affected Products

References

Published: 2026-08-17 · Source: GitHub · Feed updated: 2026-08-18
This high severity vulnerability with a CVSS score of 8.1 was published on 2026-08-17 via GitHub. Affected: maven/org.http4k:http4k-security-digest >= 6.0.0.0, < 6.50.0.0, maven/org.http4k:http4k-security-digest >= 5.0.0.0, < 5.42.0.0, maven/org.http4k:http4k-security-digest <= 4.48.2.0.
vulnfeed aggregates 11052 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.