Sceawere

Vulnerability Detail

CVE-2026-100725UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

http4k Cookie Scope Violation

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
http4k
Product
http4k
Attack Type
Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (client-side cookie store used by ClientFilters.Cookies) that does not enforce RFC 6265 scoping rules for the cookie domain, path, and Secure attributes. When a single BasicCookieStorage instance is used to talk to more than one origin or scheme, cookies stored for one origin can be sent to other origins, and cookies marked Secure can be sent over plain HTTP, potentially disclosing session cookies or other sensitive values to unauthorized hosts or network observers. Clients that use a storage instance for a single origin are not affected.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-27T02:17:20.760Z",
  "pubdate": "2026-09-27T02:17:20.760Z",
  "executiveSummary": "The http4k library is vulnerable to an improper cookie scoping flaw within the BasicCookieStorage component, used by ClientFilters.Cookies.\nThe vulnerability arises because the storage implementation fails to enforce RFC 6265 compliance regarding cookie domain, path, and Secure attribute validation.\nThis flaw allows for cross-origin and cross-scheme cookie leakage when a single BasicCookieStorage instance is shared across multiple endpoints.\nImpacts include the unauthorized disclosure of session identifiers and sensitive authentication tokens to untrusted third-party origins.\nAdditionally, cookies tagged as 'Secure' may be transmitted over unencrypted HTTP channels, exposing sensitive data to network-based eavesdropping.\nThe vulnerability affects org.http4k:http4k-core versions prior to 6.48.0.0, 5.42.0.0, and 4.51.0.0.\nExploitation requires the application to reuse a single storage instance for heterogeneous origins, potentially allowing an attacker controlling a secondary site to capture cookies intended only for a legitimate, protected domain.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the BasicCookieStorage class to validate cookie attributes against the request's origin during the retrieval process in ClientFilters.Cookies.\nIn a compliant implementation, a cookie store must verify that the domain and path attributes of a stored cookie match the requested URL and that the protocol scheme is appropriate (e.g., preventing Secure cookies from being sent over non-HTTPS connections).\nBecause BasicCookieStorage lacks these logic checks, it treats the store as a flat collection of key-value pairs without contextual scoping.\nIf a developer initializes a single instance of BasicCookieStorage and utilizes it across multiple client connections—for instance, connecting to a secure internal API and an external, untrusted third-party service—the storage instance will indiscriminately serve all previously accumulated cookies to every subsequent request.\nThe attack flow follows these steps: 1) A victim client performs an authenticated request to a target domain, storing a sensitive 'Secure' session cookie in the shared BasicCookieStorage instance. 2) The client then performs a request to a malicious or compromised origin using the same storage instance. 3) Because BasicCookieStorage performs no scoping validation, it attaches the sensitive cookies from the first request to the request sent to the attacker-controlled server. 4) The attacker captures the cookies, effectively bypassing the same-origin policy that should have been enforced by the cookie storage layer.\nThis behavior facilitates credential theft, session hijacking, and unauthorized resource access. The vulnerability is especially critical in multi-tenant environments or applications that integrate with numerous external service providers where cookie isolation is expected by default.\nThe scope of this vulnerability is limited to instances where the storage container is reused for cross-origin interactions. Applications that instantiate a dedicated, isolated BasicCookieStorage instance per specific origin are not susceptible to this leak, as the scope violation only manifests when shared storage handles multiple distinct endpoints with conflicting security requirements."
}
CVE-2026-100725: http4k Cookie Scope Violation (MEDIUM Severity, CVSS: 6.5) | Sceawere