{"id":"CVE-2026-54148","summary":"http4k: `DigestAuthProvider.verify` did not bind to request URI","details":"http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the actual request URL. An attacker who captures a valid Digest authentication response can replay it against another URL served by the same realm, bypassing the per-request-URI binding and potentially gaining unauthorized read or write access. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.","aliases":["GHSA-p28p-j94q-pg32"],"modified":"2026-09-20T11:46:40.784277611Z","published":"2026-09-18T16:09:44.361Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"4.51.0.0"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-294"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54148.json"},"references":[{"type":"WEB","url":"https://github.com/http4k/http4k/releases/tag/6.50.0.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54148.json"},{"type":"ADVISORY","url":"https://github.com/http4k/http4k/security/advisories/GHSA-p28p-j94q-pg32"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54148"},{"type":"FIX","url":"https://github.com/github/advisory-database/pull/9477"},{"type":"FIX","url":"https://github.com/http4k/http4k/commit/725f1b96978dd433348e2b149c1e72b9f5147c90"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/http4k/http4k","events":[{"introduced":"ed37b9043df6505b3369b8cb31bddbb0e7cd1b76"},{"introduced":"c2a2f9f85e704385b864a34a91adaea2a3275a2e"},{"fixed":"e41f40814305510d4f82e30bb0bcd12b9928292e"},{"fixed":"cf738c1c09ad08ec861a0bc3f2ec0d3740e4ea70"},{"fixed":"725f1b96978dd433348e2b149c1e72b9f5147c90"}],"database_specific":{"extracted_events":[{"introduced":"5.0.0.0"},{"fixed":"5.42.0.0"},{"introduced":"6.0.0.0"},{"fixed":"6.50.0.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["6.49.0.0","6.48.0.0","6.47.2.0","6.47.1.0","6.47.0.0","6.46.1.0","6.46.0.0","6.45.1.0","6.45.0.0","6.44.0.0","6.43.0.0","6.42.0.0","6.41.0.0","6.40.1.0","6.40.0.0","6.39.1.0","6.39.0.0","6.38.0.0","6.37.0.0","6.36.0.0","6.35.0.0","6.34.0.0","6.33.0.0","6.32.0.0","6.31.1.0","6.31.0.0","6.30.1.0","6.30.0.0","6.29.0.0","6.28.1.0","6.28.0.0","6.27.0.0","6.26.1.0","6.26.0.0","6.25.1.0","6.25.0.0","6.24.1.0","6.24.0.0","6.23.1.0","6.23.0.0","6.22.0.0","6.21.1.0","6.21.0.0","6.20.2.1","6.20.2.0","6.20.1.0","6.20.0.3","6.20.0.2","6.20.0.1","6.20.0.0","6.19.0.0","6.18.1.0","6.18.0.1","6.17.0.0","6.16.0.0","6.15.1.0","6.15.0.1","6.15.0.0","6.14.0.0","6.13.0.0","6.12.0.0","6.11.1.0","6.11.0.0","6.10.2.0","6.10.1.0","6.10.0.0","6.9.2.0","6.9.1.0","6.9.0.0","6.8.1.0","6.8.0.0","6.7.0.0","6.6.1.0","6.6.0.1","6.6.0.0","6.5.6.1","6.5.6.0","6.5.5.1","6.5.5.0","6.5.4.0","6.5.3.0","6.5.2.0","6.5.1.0","6.5.0.0","6.4.1.0","v6.4.1.0","6.4.0.0","v6.3.0.0","6.2.0.0","6.1.0.1","6.1.0.0","6.0.1.0","6.0.0.0","5.41.0.0","5.40.0.0","5.39.0.0","5.38.0.0","5.37.1.1","5.37.1.0","5.37.0.0","5.36.0.0","5.35.5.0","5.35.4.0","5.35.3.0","5.35.2.0","5.35.1.0","5.35.0.0","5.34.1.0","5.34.0.0","5.33.1.0","5.33.0.1","0.0.0","5.33.0.0","5.32.4.0","5.32.3.0","5.32.2.0","5.32.1.0","5.32.0.0","5.31.1.0","5.31.0.0","5.30.1.0","5.30.0.0","5.29.0.0","5.28.1.0","5.28.0.0","5.27.0.0","5.26.1.0","5.26.0.0","5.25.1.0","5.25.0.0","5.24.1.0","5.24.0.0","5.23.0.0","5.22.0.0","5.21.2.0","5.21.1.0","5.21.0.0","5.20.0.0","5.19.0.0","5.18.2.0","5.18.1.0","5.17.0.0","5.16.2.0","5.16.1.0","5.16.0.0","5.15.0.0","5.14.5.0","5.14.4.0","5.14.2.0","5.14.1.0","5.14.0.0","5.13.9.0","5.13.8.0","5.13.7.0","5.13.6.1","5.13.6.0","5.13.5.0","5.13.4.1","5.13.4.0","5.13.2.0","5.13.1.0","5.13.0.1","5.13.0.0","5.12.2.1","5.12.2.0","5.12.1.0","5.12.0.0","5.11.1.0","5.11.0.0","5.10.7.0","5.10.6.0","5.10.5.0","5.10.4.0","5.10.3.0","5.10.2.0","5.10.1.0","5.10.0.0","5.9.0.0","5.8.6.0","5.8.5.1","5.8.5.0","5.8.4.0","5.8.3.0","5.8.2.0","5.8.1.0","5.8.0.0","5.7.5.0","5.7.4.0","5.7.3.0","5.7.2.0","5.7.1.0","5.6.5.0","5.6.4.0","5.6.3.0","5.6.2.1","5.6.2.0","5.6.1.0","5.6.0.0","5.5.0.0","5.4.1.0","5.4.0.0","5.3.0.0","5.2.1.0","5.2.0.0","5.1.2.1","5.1.2.0","5.1.1.1","5.1.1.0","5.1.0.0","5.0.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54148.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"}]}