Sceawere
Vulnerability Detail
CVE-2026-100725UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
http4k Cookie Scope Violation
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 1d ago
- Vendor
- http4k
- Product
- http4k
- Attack Type
- Exposure of Sensitive Information to an Unauthorized Actor
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (client-side cookie store used by ClientFilters.Cookies) that does not enforce RFC 6265 scoping rules for the cookie domain, path, and Secure attributes. When a single BasicCookieStorage instance is used to talk to more than one origin or scheme, cookies stored for one origin can be sent to other origins, and cookies marked Secure can be sent over plain HTTP, potentially disclosing session cookies or other sensitive values to unauthorized hosts or network observers. Clients that use a storage instance for a single origin are not affected.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-27T02:17:20.760Z",
"pubdate": "2026-09-27T02:17:20.760Z",
"executiveSummary": "The http4k library is vulnerable to an improper cookie scoping flaw within the BasicCookieStorage component, used by ClientFilters.Cookies.\nThe vulnerability arises because the storage implementation fails to enforce RFC 6265 compliance regarding cookie domain, path, and Secure attribute validation.\nThis flaw allows for cross-origin and cross-scheme cookie leakage when a single BasicCookieStorage instance is shared across multiple endpoints.\nImpacts include the unauthorized disclosure of session identifiers and sensitive authentication tokens to untrusted third-party origins.\nAdditionally, cookies tagged as 'Secure' may be transmitted over unencrypted HTTP channels, exposing sensitive data to network-based eavesdropping.\nThe vulnerability affects org.http4k:http4k-core versions prior to 6.48.0.0, 5.42.0.0, and 4.51.0.0.\nExploitation requires the application to reuse a single storage instance for heterogeneous origins, potentially allowing an attacker controlling a secondary site to capture cookies intended only for a legitimate, protected domain.",
"technicalDetails": "The root cause of this vulnerability is the failure of the BasicCookieStorage class to validate cookie attributes against the request's origin during the retrieval process in ClientFilters.Cookies.\nIn a compliant implementation, a cookie store must verify that the domain and path attributes of a stored cookie match the requested URL and that the protocol scheme is appropriate (e.g., preventing Secure cookies from being sent over non-HTTPS connections).\nBecause BasicCookieStorage lacks these logic checks, it treats the store as a flat collection of key-value pairs without contextual scoping.\nIf a developer initializes a single instance of BasicCookieStorage and utilizes it across multiple client connections—for instance, connecting to a secure internal API and an external, untrusted third-party service—the storage instance will indiscriminately serve all previously accumulated cookies to every subsequent request.\nThe attack flow follows these steps: 1) A victim client performs an authenticated request to a target domain, storing a sensitive 'Secure' session cookie in the shared BasicCookieStorage instance. 2) The client then performs a request to a malicious or compromised origin using the same storage instance. 3) Because BasicCookieStorage performs no scoping validation, it attaches the sensitive cookies from the first request to the request sent to the attacker-controlled server. 4) The attacker captures the cookies, effectively bypassing the same-origin policy that should have been enforced by the cookie storage layer.\nThis behavior facilitates credential theft, session hijacking, and unauthorized resource access. The vulnerability is especially critical in multi-tenant environments or applications that integrate with numerous external service providers where cookie isolation is expected by default.\nThe scope of this vulnerability is limited to instances where the storage container is reused for cross-origin interactions. Applications that instantiate a dedicated, isolated BasicCookieStorage instance per specific origin are not susceptible to this leak, as the scope violation only manifests when shared storage handles multiple distinct endpoints with conflicting security requirements."
}