http4k
6 known vulnerabilities in http4k, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-100834 CVSS 8.2 high http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0.0 defaults the…
- CVE-2026-100725 CVSS 8.3 high http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (client-side cookie…
- CVE-2026-100724 CVSS 6.3 medium http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses substring (Contains) matching on the Host header…
- CVE-2026-54148 CVSS 8.1 high http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in…
- CVE-2026-54147 CVSS 6.5 medium http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in…
- CVE-2026-53659 CVSS 7.5 high http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip…