HIGH 8.1 GitHub
CVE-2026-54148
http4k: `DigestAuthProvider.verify` did not bind to request URI
### Impact
An issue in `DigestAuthProvider.verify`:
The `uri` parameter in the client's `Authorization: Digest …` response was not checked against the actual request URL. A captured Digest authentication response could be replayed against any other URL served by the same realm, breaking the per-request-URL binding the Digest scheme assumes.
**Who is affected:** any application using `http4k-security-digest` for HTTP Digest authentication. The bug has been present since `DigestAuthProvider` wa
Affected Products
- maven/org.http4k:http4k-security-digest >= 6.0.0.0, < 6.50.0.0
- maven/org.http4k:http4k-security-digest >= 5.0.0.0, < 5.42.0.0
- maven/org.http4k:http4k-security-digest <= 4.48.2.0
References
- https://github.com/advisories/GHSA-p28p-j94q-pg32
- https://github.com/http4k/http4k/security/advisories/GHSA-p28p-j94q-pg32
- https://github.com/http4k/http4k/commit/725f1b9697
- https://github.com/http4k/http4k/releases/tag/6.50.0.0
This high severity vulnerability with a CVSS score of 8.1 was published on 2026-08-17 via GitHub. Affected: maven/org.http4k:http4k-security-digest >= 6.0.0.0, < 6.50.0.0, maven/org.http4k:http4k-security-digest >= 5.0.0.0, < 5.42.0.0, maven/org.http4k:http4k-security-digest <= 4.48.2.0.
vulnfeed aggregates 11052 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.