CVE-2026-100834 Overview
CVE-2026-100834 affects http4k's Digest authentication module (org.http4k:http4k-security-digest) prior to versions 6.48.0.0, 5.42.0.0, and 4.51.0.0. The nonceVerifier parameter of ServerFilters.DigestAuth and DigestAuthProvider defaults to { true }, causing every nonce to be accepted regardless of value, age, or prior use. Applications relying on this default lack replay protection on Digest authentication. An attacker who captures a valid Authorization: Digest header, through network observation or log access, can replay it indefinitely against the same protected resource. The weakness is classified as Authentication Bypass by Capture-replay [CWE-294].
Critical Impact
Captured Digest credentials remain valid indefinitely, allowing attackers to replay authentication headers and impersonate legitimate users against protected resources.
Affected Products
- http4k org.http4k:http4k-security-digest versions prior to 6.48.0.0
- http4k org.http4k:http4k-security-digest versions prior to 5.42.0.0
- http4k org.http4k:http4k-security-digest versions prior to 4.51.0.0
Discovery Timeline
- 2026-09-27 - CVE-2026-100834 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-100834
Vulnerability Analysis
HTTP Digest authentication, defined in RFC 7616, protects against replay attacks by issuing server-generated nonces that clients must incorporate into their challenge response. The server validates each nonce for freshness, prior use, and binding to the authenticating session. http4k's Digest module exposes a nonceVerifier: NonceVerifier parameter to let applications implement this validation.
The affected versions supply a default implementation of { true }, a lambda that unconditionally approves every nonce. Developers who instantiate ServerFilters.DigestAuth or DigestAuthProvider without explicitly supplying their own verifier inherit a configuration where any previously issued credential header is treated as valid for the lifetime of the resource.
Root Cause
The root cause is an insecure default in the Kotlin API signature. By assigning nonceVerifier: NonceVerifier = { true } as a default argument, the library makes it trivial for developers to construct a Digest filter that silently discards the replay-protection step. The vulnerability is a design flaw rather than a parsing or memory error.
Attack Vector
Exploitation is network-based and does not require privileges or user interaction. An attacker who observes a single successful Authorization: Digest request, through traffic capture, proxy logs, or server access logs, can resend the same header to the protected endpoint and receive the same authenticated response. The replay works across sessions until the credentials themselves rotate.
// Patch: core/security/digest/.../serverFilterExtensions.kt
fun ServerFilters.DigestAuth(
realm: String,
passwordLookup: (String) -> String?,
- qop: List<Qop> = listOf(Qop.Auth),
- digestMode: DigestMode = DigestMode.Standard,
- nonceGenerator: NonceGenerator = SECURE_NONCE,
- nonceVerifier: NonceVerifier = { true },
+ qop: List<Qop> = listOf(Auth),
+ digestMode: DigestMode = Standard,
+ nonceGenerator: NonceGenerator,
+ nonceVerifier: NonceVerifier,
algorithm: String = "MD5",
usernameKey: RequestLens<String>? = null,
): Filter {
Source: http4k commit 4f904b4692. The fix removes the insecure defaults, forcing developers to pass explicit nonceGenerator and nonceVerifier implementations.
// Patch: DigestAuthProvider.kt
private val nonceGenerator: NonceGenerator,
- private val nonceVerifier: NonceVerifier = { true },
+ private val nonceVerifier: NonceVerifier,
private val digestMode: DigestMode = DigestMode.Standard
Source: http4k commit 4f904b4692.
Detection Methods for CVE-2026-100834
Indicators of Compromise
- Repeated inbound requests carrying identical Authorization: Digest header values, including matching nonce, nc, and response fields, from the same or differing source addresses.
- Successful authenticated requests whose nc (nonce count) does not increment monotonically across sessions.
- Access to protected endpoints from IP addresses or user agents that never performed the initial WWW-Authenticate challenge handshake.
Detection Strategies
- Perform dependency scanning on Kotlin and JVM projects to identify org.http4k:http4k-security-digest versions below 4.51.0.0, 5.42.0.0, or 6.48.0.0.
- Inspect application source for ServerFilters.DigestAuth(...) or DigestAuthProvider(...) invocations that omit a nonceVerifier argument.
- Correlate HTTP access logs to flag duplicate Digest response tokens observed outside a normal request-reply window.
Monitoring Recommendations
- Forward web server and reverse proxy logs to a central analytics platform and alert on Digest authentication headers reused beyond a short validity window.
- Instrument the application to log every nonce issuance and verification outcome, enabling retroactive replay analysis.
- Monitor for anomalous geographic or client-fingerprint drift on sessions authenticated with Digest.
How to Mitigate CVE-2026-100834
Immediate Actions Required
- Upgrade org.http4k:http4k-security-digest to 6.48.0.0, 5.42.0.0, or 4.51.0.0 depending on the major version in use.
- Audit all call sites of ServerFilters.DigestAuth and DigestAuthProvider and supply an explicit nonceVerifier that enforces single-use and time-bound nonces.
- Rotate any credentials and session material that may have been exposed through replayable Digest headers.
Patch Information
The fix is published in http4k releases 6.48.0.0, 5.42.0.0, and 4.51.0.0. Breaking changes remove the insecure defaults for nonceGenerator and nonceVerifier, requiring explicit arguments. Reference the GitHub Security Advisory GHSA-c7jm-38gq-h67h, the VulnCheck Advisory, and the upstream patches in commit 4f904b4692 and commit 8a52b615b1.
Workarounds
- Supply a custom NonceVerifier that tracks issued nonces, enforces single-use semantics, and expires entries after a short interval such as 60 seconds.
- Front the application with a reverse proxy or API gateway that performs independent replay detection on Authorization: Digest headers.
- Where feasible, replace Digest authentication with a stronger scheme such as mutual TLS or bearer tokens bound to short-lived sessions.
# Gradle: pin a patched http4k version
# build.gradle.kts
dependencies {
implementation("org.http4k:http4k-security-digest:6.48.0.0")
}
# Maven
# <dependency>
# <groupId>org.http4k</groupId>
# <artifactId>http4k-security-digest</artifactId>
# <version>6.48.0.0</version>
# </dependency>
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
