Junglewise Threat Intelligence

CVE-2026-100834: http4k Digest authentication nonce verification bypass

CVE-2026-100834 · Severity: medium · CVSS 5.9 · Published 2026-09-27

Technologies: Http4k-Security-Digest. Vendors: Http4k.

Executive brief

http4k's Digest authentication security module defaults to accepting all authentication nonces without validation. This allows attackers who capture a valid Digest authentication response from network traffic or logs to replay it indefinitely against protected resources, bypassing intended replay attack protection and potentially gaining unauthorized access.

Technical details

The nonceVerifier parameter in ServerFilters.DigestAuth and DigestAuthProvider defaults to accepting all nonces (always returns true), eliminating replay protection. An attacker can reuse a captured Authorization header indefinitely without network access required beyond initial sniffing. The fix requires explicitly configuring a proper nonce verifier; versions 4.51.0.0, 5.42.0.0, and 6.48.0.0 remove the unsafe default.

Affected products

  • http4k http4k-security-digest before 4.51.0.0, 5.42.0.0, and 6.48.0.0

Timeline

  • 2026-09-27: disclosed

References

Related threats