THREAT OPS › Threat News › [GHSA] GHSA-vxxm-wwqh-mh47 (medium) — http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI
[GHSA] GHSA-vxxm-wwqh-mh47 (medium) — http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI
GHSA-vxxm-wwqh-mh47 Severity: medium CVE: CVE-2026-54147
http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI
### Impact
An issue in `DigestAuthProvider.verify`:
**Algorithm silently forced to MD5.** The configured `algorithm` parameter was ignored — every verification used MD5 regardless of configuration. Deployments believing they were running SHA
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-54147cve
- enterprise@http4k.orgemail
- 6.50.0.0ipv4
- 5.42.0.0ipv4
- 4.51.0.0ipv4
Original source: https://github.com/advisories/GHSA-vxxm-wwqh-mh47