THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p28p-j94q-pg32 (high) — http4k: `DigestAuthProvider.verify` did not bind to request URI

[GHSA] GHSA-p28p-j94q-pg32 (high) — http4k: `DigestAuthProvider.verify` did not bind to request URI

medgithub_advisoriesPublished 2026-08-17

GHSA-p28p-j94q-pg32 Severity: high CVE: CVE-2026-54148

http4k: `DigestAuthProvider.verify` did not bind to request URI

### Impact

An issue in `DigestAuthProvider.verify`:

The `uri` parameter in the client's `Authorization: Digest …` response was not checked against the actual request URL. A captured Digest authentication response could be replayed against any other URL served by the same realm

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p28p-j94q-pg32