http4k(Maven 构件 org.http4k:http4k-core)在 6.48.0.0、5.42.0.0 和 4.51.0.0 之前的版本中,包含一个 BasicCookieStorage 实现(由 ClientFilters.Cookies 使用,作为客户端侧的 cookie 存储),该实现未强制执行 RFC 6265 中关于 cookie 的 domain、path 和 Secure 属性的作用域规则。当使用单个 BasicCookieStorage 实例与多个来源(origin)或协议(schem
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100834 | 5.9 MEDIUM | http4k before 6.48.0.0 Digest Authentication Replay Protection Bypass |
| CVE-2026-100724 | 5.4 MEDIUM | http4k before 6.49.0.0 Host Header Routing Bypass via reverseProxy |
No comments yet