在 http4k 的摘要认证模块(org.http4k:http4k-security-digest)中,低于版本 6.48.0.0、5.42.0.0 和 4.51.0.0 的默认配置将 ServerFilters.DigestAuth 和 DigestAuthProvider 的 nonceVerifier 参数设为 { true },这意味着所有 nonce 值均会被接受,无论其内容、有效期或是否已被使用。依赖于该默认设置的 application 在摘要认证中缺乏重放保护:攻击者若能够捕获有效的 'Autho
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100725 | 6.5 MEDIUM | http4k before 6.48.0.0 Cookie Scoping Bypass via BasicCookieStorage |
| CVE-2026-100724 | 5.4 MEDIUM | http4k before 6.49.0.0 Host Header Routing Bypass via reverseProxy |
No comments yet