http4k(Maven 包 org.http4k:http4k-core)在 6.49.0.0、5.42.0.0 和 4.51.0.0 之前的版本中,默认在 reverseProxy() 和 reverseProxyRouting() 方法中对 Host 头使用子串(Contains)匹配机制来分发请求至已配置的虚拟主机。如果这些函数被部署为面向公众的入站 HTTP 处理程序,并配置了两个或多个虚拟主机,则远程攻击者可以提供一个仅包含某个已配置虚拟主机名称的 Host 头(例如,对于配置为 “admin” 的虚拟
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100725 | 6.5 MEDIUM | http4k before 6.48.0.0 Cookie Scoping Bypass via BasicCookieStorage |
| CVE-2026-100834 | 5.9 MEDIUM | http4k before 6.48.0.0 Digest Authentication Replay Protection Bypass |
No comments yet