VYPR

Maven package

org.http4k/http4k-security-digest

pkg:maven/org.http4k/http4k-security-digest

Vulnerabilities (2)

  • CVE-2026-54148HigSep 18, 2026
    affected >= 6.0.0.0, < 6.50.0.0fixed 6.50.0.0

    http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the actual request URL. An attacker who capture

  • CVE-2026-54147MedSep 18, 2026
    affected >= 6.0.0.0, < 6.50.0.0fixed 6.50.0.0

    http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response with hardcoded MD5. Deployments configured for