Digest Authentication Replay Protection Bypass in http4k by Affected Vendor
CVE-2026-100834
8.2HIGH
What is CVE-2026-100834?
The vulnerability in http4k's Digest authentication module allows attackers to bypass replay protection, as the nonceVerifier parameter defaults to accept all nonce values. This means that valid 'Authorization: Digest' responses can be reused indefinitely against the same protected resource, posing a significant risk for applications utilizing this authentication method. Users are encouraged to update to the latest versions to mitigate this security issue.
Affected Version(s)
http4k 0 < 6.48.0.0
http4k 0 < 5.42.0.0
http4k 0 < 4.51.0.0
