CVE-2026-54147

Source
https://cve.org/CVERecord?id=CVE-2026-54147
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54147.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54147
Aliases
Published
2026-09-18T16:10:40Z
Modified
2026-09-26T03:30:16Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N CVSS Calculator
Summary
http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI
Details

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response with hardcoded MD5. Deployments configured for SHA-256 therefore receive weaker MD5-based verification, exposing Digest authentication to collision-related attack paths that depend on the hash function's collision resistance. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-327"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54147.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "fixed":  "4.51.0.0"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/http4k/http4k

Affected ranges

Type
GIT
Repo
https://github.com/http4k/http4k
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "5.0.0.0"
        },
        {
            "fixed":  "5.42.0.0"
        },
        {
            "introduced":  "6.0.0.0"
        },
        {
            "fixed":  "6.50.0.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.0.0
5.*
5.0.0.0
5.1.0.0
5.1.1.0
5.1.1.1
5.1.2.0
5.1.2.1
5.10.0.0
5.10.1.0
5.10.2.0
5.10.3.0
5.10.4.0
5.10.5.0
5.10.6.0
5.10.7.0
5.11.0.0
5.11.1.0
5.12.0.0
5.12.1.0
5.12.2.0
5.12.2.1
5.13.0.0
5.13.0.1
5.13.1.0
5.13.2.0
5.13.4.0
5.13.4.1
5.13.5.0
5.13.6.0
5.13.6.1
5.13.7.0
5.13.8.0
5.13.9.0
5.14.0.0
5.14.1.0
5.14.2.0
5.14.4.0
5.14.5.0
5.15.0.0
5.16.0.0
5.16.1.0
5.16.2.0
5.17.0.0
5.18.1.0
5.18.2.0
5.19.0.0
5.2.0.0
5.2.1.0
5.20.0.0
5.21.0.0
5.21.1.0
5.21.2.0
5.22.0.0
5.23.0.0
5.24.0.0
5.24.1.0
5.25.0.0
5.25.1.0
5.26.0.0
5.26.1.0
5.27.0.0
5.28.0.0
5.28.1.0
5.29.0.0
5.3.0.0
5.30.0.0
5.30.1.0
5.31.0.0
5.31.1.0
5.32.0.0
5.32.1.0
5.32.2.0
5.32.3.0
5.32.4.0
5.33.0.0
5.33.0.1
5.33.1.0
5.34.0.0
5.34.1.0
5.35.0.0
5.35.1.0
5.35.2.0
5.35.3.0
5.35.4.0
5.35.5.0
5.36.0.0
5.37.0.0
5.37.1.0
5.37.1.1
5.38.0.0
5.39.0.0
5.4.0.0
5.4.1.0
5.40.0.0
5.41.0.0
5.5.0.0
5.6.0.0
5.6.1.0
5.6.2.0
5.6.2.1
5.6.3.0
5.6.4.0
5.6.5.0
5.7.1.0
5.7.2.0
5.7.3.0
5.7.4.0
5.7.5.0
5.8.0.0
5.8.1.0
5.8.2.0
5.8.3.0
5.8.4.0
5.8.5.0
5.8.5.1
5.8.6.0
5.9.0.0
6.*
6.0.0.0
6.0.1.0
6.1.0.0
6.1.0.1
6.10.0.0
6.10.1.0
6.10.2.0
6.11.0.0
6.11.1.0
6.12.0.0
6.13.0.0
6.14.0.0
6.15.0.0
6.15.0.1
6.15.1.0
6.16.0.0
6.17.0.0
6.18.0.1
6.18.1.0
6.19.0.0
6.2.0.0
6.20.0.0
6.20.0.1
6.20.0.2
6.20.0.3
6.20.1.0
6.20.2.0
6.20.2.1
6.21.0.0
6.21.1.0
6.22.0.0
6.23.0.0
6.23.1.0
6.24.0.0
6.24.1.0
6.25.0.0
6.25.1.0
6.26.0.0
6.26.1.0
6.27.0.0
6.28.0.0
6.28.1.0
6.29.0.0
6.30.0.0
6.30.1.0
6.31.0.0
6.31.1.0
6.32.0.0
6.33.0.0
6.34.0.0
6.35.0.0
6.36.0.0
6.37.0.0
6.38.0.0
6.39.0.0
6.39.1.0
6.4.0.0
6.4.1.0
6.40.0.0
6.40.1.0
6.41.0.0
6.42.0.0
6.43.0.0
6.44.0.0
6.45.0.0
6.45.1.0
6.46.0.0
6.46.1.0
6.47.0.0
6.47.1.0
6.47.2.0
6.48.0.0
6.49.0.0
6.5.0.0
6.5.1.0
6.5.2.0
6.5.3.0
6.5.4.0
6.5.5.0
6.5.5.1
6.5.6.0
6.5.6.1
6.6.0.0
6.6.0.1
6.6.1.0
6.7.0.0
6.8.0.0
6.8.1.0
6.9.0.0
6.9.1.0
6.9.2.0
v6.*
v6.3.0.0
v6.4.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54147.json"