CVE-2026-54147 Overview
CVE-2026-54147 affects http4k, a functional toolkit for building HTTP applications in Kotlin. The DigestAuthProvider.verify function in the http4k-security-digest module ignores its configured algorithm parameter. Instead, it hardcodes MD5 for every Digest response verification. Deployments configured for SHA-256 therefore fall back to weaker MD5-based verification. This exposes Digest authentication to collision-related attack paths whose feasibility depends on the underlying hash function's collision resistance. The issue is tracked under [CWE-327: Use of a Broken or Risky Cryptographic Algorithm]. Fixed releases are 4.51.0.0, 5.42.0.0, and 6.50.0.0.
Critical Impact
Applications relying on SHA-256 Digest authentication silently verify credentials with MD5, undermining integrity guarantees expected from the configured algorithm.
Affected Products
- http4k http4k-security-digest versions prior to 4.51.0.0
- http4k http4k-security-digest versions prior to 5.42.0.0
- http4k http4k-security-digest versions prior to 6.50.0.0
Discovery Timeline
- 2026-09-18 - CVE-2026-54147 published to NVD
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-54147
Vulnerability Analysis
The DigestAuthProvider class is responsible for verifying HTTP Digest Access Authentication credentials submitted by clients. Digest authentication supports multiple hash algorithms, including MD5 and SHA-256, negotiated between the server and client. The provider accepts an algorithm parameter at configuration time and advertises that algorithm in WWW-Authenticate challenges. However, the verification path instantiates a MessageDigest using the literal string "MD5" rather than the configured algorithm. Any deployment that opts into SHA-256 receives MD5 verification regardless. An attacker who can construct MD5 collisions against a target request could forge a valid Digest response that the server accepts.
Root Cause
The defect is a hardcoded string in the verification routine. The verify method constructs a DigestEncoder from MessageDigest.getInstance("MD5") instead of MessageDigest.getInstance(algorithm). The configured algorithm is used elsewhere in the provider, so mismatched clients are rejected by the algorithm check, but successful matches are still validated with MD5. This is a canonical [CWE-327] weakness.
Attack Vector
Exploitation requires network access to the protected endpoint and is high complexity. An attacker must produce an MD5 collision that satisfies the Digest challenge parameters (nonce, method, URI, and body qop values). Successful forgery yields authenticated access with the integrity impact of the compromised account, without requiring valid credentials or user interaction.
// Source: https://github.com/http4k/http4k/commit/65d23d99fc5afbe34f29d8f61d0a003fbebb381c
// Patch to DigestAuthProvider.kt — uses the configured algorithm instead of hardcoded MD5
?.let { DigestCredential.fromHeader(it) }
fun verify(credentials: DigestCredential, method: Method): Boolean {
- val digestEncoder = DigestEncoder(MessageDigest.getInstance("MD5"))
+ val digestEncoder = DigestEncoder(MessageDigest.getInstance(algorithm))
// verify credentials pertain to this provider
if (credentials.algorithm != null && credentials.algorithm != algorithm) return false
Detection Methods for CVE-2026-54147
Indicators of Compromise
- Successful Digest authentication events where the WWW-Authenticate challenge advertised SHA-256 but the client Authorization header contains an algorithm=MD5 response.
- Repeated authentication attempts with identical nonce values but varying request bodies of equal length, suggesting collision probing.
- Unexpected HTTP 200 responses to Digest-authenticated endpoints from clients that do not appear in prior baselines.
Detection Strategies
- Perform a software composition analysis (SCA) scan of Kotlin and JVM projects to enumerate http4k-security-digest versions below 4.51.0.0, 5.42.0.0, or 6.50.0.0.
- Inspect service configuration for DigestAuthProvider instances that pass SHA-256 as the algorithm parameter, since these are the deployments materially affected by the downgrade.
- Add a web application firewall rule to flag Authorization: Digest headers whose algorithm value disagrees with the server's advertised algorithm.
Monitoring Recommendations
- Log the negotiated Digest algorithm and outcome for every authentication event to enable retrospective hunting.
- Alert on bursts of failed Digest authentications from a single source, which may indicate collision generation attempts.
- Track dependency updates in CI/CD pipelines to ensure http4k library versions remain above the fixed releases.
How to Mitigate CVE-2026-54147
Immediate Actions Required
- Upgrade http4k to 4.51.0.0, 5.42.0.0, or 6.50.0.0 depending on your active major version.
- Audit all DigestAuthProvider configurations and confirm that the algorithm parameter is now honored end-to-end after upgrade.
- Rotate any shared secrets used by Digest-authenticated services if collision-based forgery is suspected.
Patch Information
The fix is committed in http4k repository commit 65d23d99fc5afbe34f29d8f61d0a003fbebb381c and released in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0. See the GitHub Security Advisory GHSA-vxxm-wwqh-mh47 and the http4k 6.50.0.0 release notes for the authoritative fix references.
Workarounds
- If immediate upgrade is not possible, front the affected service with a reverse proxy that terminates authentication using a hardened mechanism such as mutual TLS or OAuth 2.0 bearer tokens.
- Restrict network exposure of Digest-authenticated endpoints to trusted internal networks until the library is patched.
- Consider disabling Digest authentication and switching to Basic authentication over TLS as a temporary measure, since the configured hash guarantee cannot be relied on.
# Gradle dependency pin — update to a fixed http4k release
# build.gradle.kts
dependencies {
implementation("org.http4k:http4k-security-digest:6.50.0.0")
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
