THREAT OPS › Threat News › [GHSA] GHSA-p28p-j94q-pg32 (high) — http4k: `DigestAuthProvider.verify` did not bind to request URI
[GHSA] GHSA-p28p-j94q-pg32 (high) — http4k: `DigestAuthProvider.verify` did not bind to request URI
GHSA-p28p-j94q-pg32 Severity: high CVE: CVE-2026-54148
http4k: `DigestAuthProvider.verify` did not bind to request URI
### Impact
An issue in `DigestAuthProvider.verify`:
The `uri` parameter in the client's `Authorization: Digest …` response was not checked against the actual request URL. A captured Digest authentication response could be replayed against any other URL served by the same realm
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-54148cve
- enterprise@http4k.orgemail
- 6.50.0.0ipv4
- 5.42.0.0ipv4
- 4.51.0.0ipv4
Original source: https://github.com/advisories/GHSA-p28p-j94q-pg32