{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-100834","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-09-26T23:23:03.410Z","datePublished":"2026-09-27T01:28:32.781Z","dateUpdated":"2026-09-27T01:28:32.781Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-09-27T01:28:32.781Z"},"datePublic":"2026-06-16T00:00:00.000Z","title":"http4k before 6.48.0.0 Digest Authentication Replay Protection Bypass","descriptions":[{"lang":"en","value":"http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0.0 defaults the nonceVerifier parameter of ServerFilters.DigestAuth and DigestAuthProvider to { true }, so every nonce is accepted regardless of its value, age, or prior use. Applications relying on this default have no replay protection on Digest authentication: an attacker who can capture a valid 'Authorization: Digest' response (for example by observing network traffic or reading logs) can replay it indefinitely against the same protected resource."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Authentication Bypass by Capture-replay","cweId":"CWE-294","type":"CWE"}]}],"affected":[{"vendor":"http4k","product":"http4k","defaultStatus":"unaffected","packageURL":"pkg:maven/org.http4k/http4k-security-digest","versions":[{"version":"0","status":"affected","versionType":"custom","lessThan":"6.48.0.0"},{"version":"6.48.0.0","status":"unaffected","versionType":"custom"}]},{"vendor":"http4k","product":"http4k","defaultStatus":"unaffected","packageURL":"pkg:maven/org.http4k/http4k-security-digest","versions":[{"version":"0","status":"affected","versionType":"custom","lessThan":"5.42.0.0"},{"version":"5.42.0.0","status":"unaffected","versionType":"custom"}]},{"vendor":"http4k","product":"http4k","defaultStatus":"unaffected","packageURL":"pkg:maven/org.http4k/http4k-security-digest","versions":[{"version":"0","status":"affected","versionType":"custom","lessThan":"4.51.0.0"},{"version":"4.51.0.0","status":"unaffected","versionType":"custom"}]}],"metrics":[{"cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","exploitMaturity":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS"},{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"},"format":"CVSS"}],"references":[{"url":"https://github.com/http4k/http4k/security/advisories/GHSA-c7jm-38gq-h67h","tags":["vendor-advisory"],"name":"GitHub Security Advisory (GHSA-c7jm-38gq-h67h)"},{"url":"https://github.com/http4k/http4k/commit/8a52b615b1","tags":["patch"],"name":"Patch Commit"},{"url":"https://github.com/http4k/http4k/commit/4f904b4692","tags":["patch"],"name":"Patch Commit"},{"name":"VulnCheck Advisory: http4k before 6.48.0.0 Digest Authentication Replay Protection Bypass","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/http4k-before-6.48.0.0-digest-authentication-replay-protection-bypass"}],"x_generator":{"engine":"vulncheck-endgame"}}}}