Sceawere

Vulnerability Detail

CVE-2026-100834UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Digest Auth Replay Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
1d ago
Vendor
http4k
Product
http4k
Attack Type
Authentication Bypass by Capture-replay
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0.0 defaults the nonceVerifier parameter of ServerFilters.DigestAuth and DigestAuthProvider to { true }, so every nonce is accepted regardless of its value, age, or prior use. Applications relying on this default have no replay protection on Digest authentication: an attacker who can capture a valid 'Authorization: Digest' response (for example by observing network traffic or reading logs) can replay it indefinitely against the same protected resource.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-09-27T02:17:21.487Z",
  "pubdate": "2026-09-27T02:17:21.487Z",
  "executiveSummary": "The http4k-security-digest library contains a critical security misconfiguration where the default nonce verification logic fails to validate the integrity and uniqueness of authentication tokens.\nThe vulnerability involves the default configuration of the nonceVerifier parameter in ServerFilters.DigestAuth and DigestAuthProvider, which defaults to a permissive state that accepts all nonces regardless of age, origin, or previous use.\nThis flaw effectively disables replay protection for Digest authentication, allowing unauthorized actors to perform session hijacking or unauthorized access by reusing intercepted Authorization headers.\nAffected products include org.http4k:http4k-security-digest versions prior to 6.48.0.0, 5.42.0.0, and 4.51.0.0.\nThe risk implication is significant, as an attacker with access to network traffic logs or plaintext capture can impersonate legitimate users indefinitely without the need for credentials.\nNo complex exploitation is required; the vulnerability is an inherent flaw in the library's default implementation logic, which assumes that all presented nonces are valid without further backend state verification.",
  "technicalDetails": "The root cause of this vulnerability lies in the default implementation of the nonceVerifier parameter within the http4k-security-digest module. By default, the library initializes this verifier as a constant function returning 'true' ({ true }). This bypasses the security requirements of the Digest access authentication protocol defined in RFC 7616, which necessitates that the server track and validate the nonce value to prevent replay attacks.\nIn a secure Digest authentication flow, the server generates a nonce and sends it to the client. The client then incorporates this nonce into the hashed response. Upon receiving the response, the server must verify that the nonce is correctly signed, matches a recently issued nonce, and has not already been used. Because the vulnerable implementation returns true for any input, the verification layer performs no state validation. It ignores the server-side expectation of nonce freshness, sequence, or uniqueness.\nThe attack flow follows a straightforward interception pattern. An attacker monitors network communications (e.g., via man-in-the-middle or access to log aggregators) to capture a valid 'Authorization: Digest' header transmitted by a legitimate user. Because the server-side nonceVerifier accepts any string, the attacker can replay this header in subsequent HTTP requests to the same protected endpoint. The application processes the request, computes the digest, and finds the credentials valid. Since the replay protection mechanism is effectively a no-op, the application grants the request as if it were a legitimate, new authentication attempt.\nThis vulnerability is present in the vulnerable component logic of DigestAuthProvider and ServerFilters.DigestAuth. Because the defect exists at the library's foundational authentication layer, it affects any http4k application using the default digest configuration. The exposure is network-based; any actor capable of sniffing traffic or accessing application logs containing authentication headers can execute this attack. The privilege level required is merely the ability to reach the protected service endpoint. Post-exploitation, the attacker gains full access to the resources afforded to the hijacked user account, as the server treats the replayed credentials as authentic."
}
CVE-2026-100834: Digest Auth Replay Vulnerability (MEDIUM Severity, CVSS: 5.9) | Sceawere