Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100725— http4k before 6.48.0.0 Cookie Scoping Bypass via BasicCookieStorage

Quick assessment

Affected
http4k http4k
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

http4k(Maven 构件 org.http4k:http4k-core)在 6.48.0.0、5.42.0.0 和 4.51.0.0 之前的版本中,包含一个 BasicCookieStorage 实现(由 ClientFilters.Cookies 使用,作为客户端侧的 cookie 存储),该实现未强制执行 RFC 6265 中关于 cookie 的 domain、path 和 Secure 属性的作用域规则。当使用单个 BasicCookieStorage 实例与多个来源(origin)或协议(schem

CVSS 6.5 · Medium EPSS 0.24% · P13

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100725

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
http4k before 6.48.0.0 Cookie Scoping Bypass via BasicCookieStorage
Source: CVE Program / CVE List V5
Vulnerability Description
http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (client-side cookie store used by ClientFilters.Cookies) that does not enforce RFC 6265 scoping rules for the cookie domain, path, and Secure attributes. When a single BasicCookieStorage instance is used to talk to more than one origin or scheme, cookies stored for one origin can be sent to other origins, and cookies marked Secure can be sent over plain HTTP, potentially disclosing session cookies or other sensitive values to unauthorized hosts or network observers. Clients that use a storage instance for a single origin are not affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
http4k http4k 0 ~ 6.48.0.0 -
http4k http4k 0 ~ 5.42.0.0 -
http4k http4k 0 ~ 4.51.0.0 -

II. Public POCs for CVE-2026-100725

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100725

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100725 (1)

Other References for CVE-2026-100725 (2)

Same Patch Batch · http4k · 2026-09-27 · 3 CVEs total

CVE-2026-100834 5.9 MEDIUM http4k before 6.48.0.0 Digest Authentication Replay Protection Bypass
CVE-2026-100724 5.4 MEDIUM http4k before 6.49.0.0 Host Header Routing Bypass via reverseProxy

IV. Related Vulnerabilities

V. Comments for CVE-2026-100725

No comments yet


Leave a comment