CVE-2026-100725 Overview
CVE-2026-100725 affects the http4k library distributed as the Maven artifact org.http4k:http4k-core. The BasicCookieStorage class, used by ClientFilters.Cookies, does not enforce RFC 6265 scoping rules for cookie domain, path, and Secure attributes. When a single storage instance communicates with multiple origins or schemes, cookies set by one origin can be transmitted to unrelated origins. Cookies marked Secure can also be sent over plain HTTP connections. This behavior can disclose session cookies and other sensitive values to unauthorized hosts or passive network observers. The flaw is categorized under [CWE-200] (Exposure of Sensitive Information to an Unauthorized Actor).
Critical Impact
Session cookies and Secure-flagged credentials can leak to foreign origins or be transmitted in cleartext when a shared BasicCookieStorage instance services multiple destinations.
Affected Products
- org.http4k:http4k-core versions prior to 4.51.0.0
- org.http4k:http4k-core versions prior to 5.42.0.0
- org.http4k:http4k-core versions prior to 6.48.0.0
Discovery Timeline
- 2026-09-27 - CVE-2026-100725 published to the National Vulnerability Database
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-100725
Vulnerability Analysis
http4k is a functional HTTP toolkit for the JVM. Client code typically opts into automatic cookie handling by chaining ClientFilters.Cookies with a CookieStorage implementation. The shipped BasicCookieStorage persists cookies without honoring the scoping metadata required by RFC 6265. When outbound requests are prepared, the filter attaches stored cookies without validating that the request Host, path prefix, or scheme matches the attributes recorded at the time of Set-Cookie. An application that reuses one BasicCookieStorage instance across a multi-tenant HTTP client, a proxy, or a crawler will attach cookies intended for a.example.com to requests destined for b.example.com. Cookies issued with the Secure attribute are likewise emitted over http:// targets. Downstream consequences include unauthorized session reuse, credential exposure to attacker-controlled endpoints, and interception by passive network observers on untrusted paths.
Root Cause
The root cause is missing enforcement of RFC 6265 Section 5.4 rules inside BasicCookieStorage. The class returns the full set of stored cookies regardless of request origin, path, or scheme, delegating no filtering responsibility to ClientFilters.Cookies. There is no per-cookie binding to the Domain, Path, or Secure attributes received in the originating response.
Attack Vector
Exploitation requires an application to reuse a single BasicCookieStorage instance across multiple origins or schemes. An attacker who controls or observes a secondary origin that the client contacts can harvest session cookies originally issued by a trusted origin. The attack is remote and requires no authentication, but it depends on the victim application's architecture, which raises attack complexity.
import org.http4k.events.Events
import org.http4k.events.HttpEvent.Outgoing
import org.http4k.filter.GzipCompressionMode.Memory
-import org.http4k.filter.cookie.BasicCookieStorage
import org.http4k.filter.cookie.CookieStorage
import org.http4k.filter.cookie.LocalCookie
+import org.http4k.filter.cookie.DefaultCookieStorage
import org.http4k.lens.Header.CONTENT_TYPE
import org.http4k.lens.StringBiDiMappings
import org.http4k.routing.ResponseWithContext
Source: http4k commit 6a9b44d743. The fix replaces BasicCookieStorage with a new DefaultCookieStorage that enforces RFC 6265 scoping when storing and emitting cookies.
Detection Methods for CVE-2026-100725
Indicators of Compromise
- Outbound HTTP requests from a Java or Kotlin service that carry Cookie headers destined for a host that did not issue those cookies.
- Set-Cookie values flagged Secure appearing in plaintext http:// requests originating from http4k clients.
- Unexpected cross-tenant session reuse recorded in upstream application logs or identity provider telemetry.
Detection Strategies
- Perform dependency scanning on build manifests for org.http4k:http4k-core at versions below 4.51.0.0, 5.42.0.0, or 6.48.0.0.
- Inspect source code for references to BasicCookieStorage and instances where a single storage object is passed into ClientFilters.Cookies for more than one destination.
- Capture egress traffic in staging environments and verify that cookie scoping matches the issuing origin.
Monitoring Recommendations
- Alert on application logs showing shared cookie jar initialization across multiple HttpHandler instances with different base URLs.
- Monitor outbound TLS downgrades or plaintext requests carrying session identifiers.
- Track authentication anomalies at identity providers that indicate the same session cookie being presented from unexpected service paths.
How to Mitigate CVE-2026-100725
Immediate Actions Required
- Upgrade org.http4k:http4k-core to 4.51.0.0, 5.42.0.0, or 6.48.0.0 depending on the major version in use.
- Replace all references to BasicCookieStorage with DefaultCookieStorage in client filter configurations.
- Audit running services for shared cookie storage instances and rotate any session credentials that may have leaked.
Patch Information
The upstream fix is published in GitHub Security Advisory GHSA-pr33-38xx-6r26 and the corresponding patch commit 6a9b44d743. Technical details and version mapping are also documented in the VulnCheck advisory for http4k.
Workarounds
- Instantiate a distinct CookieStorage object per target origin and per scheme instead of sharing one storage instance.
- Avoid using BasicCookieStorage in any client that contacts more than one host; restrict its use to single-origin clients.
- Enforce HTTPS at the client transport layer so that Secure cookies cannot be transmitted over plaintext channels.
# Gradle dependency pin to a fixed release
implementation("org.http4k:http4k-core:6.48.0.0")
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
