Maven package
org.http4k/http4k-security-digest
pkg:maven/org.http4k/http4k-security-digest
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-54148 | Hig | 8.1 | >= 6.0.0.0, < 6.50.0.0 | 6.50.0.0 | Sep 18, 2026 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the actual request URL. An attacker who capture | |
| CVE-2026-54147 | Med | 6.5 | >= 6.0.0.0, < 6.50.0.0 | 6.50.0.0 | Sep 18, 2026 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response with hardcoded MD5. Deployments configured for |
- affected >= 6.0.0.0, < 6.50.0.0fixed 6.50.0.0
http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the actual request URL. An attacker who capture
- affected >= 6.0.0.0, < 6.50.0.0fixed 6.50.0.0
http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response with hardcoded MD5. Deployments configured for