CVE-2026-54147
6.5 MEDIUMpublic exploit availablePublished 2026-09-18 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response with hardcoded MD5. Deployments configured for SHA-256 therefore receive weaker MD5-based verification, exposing Digest authentication to collision-related attack paths that depend on the hash function's collision resistance. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.50.0.0.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Weaknesses
CWE-327
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2024-56344
- MEDIUMCVE-2025-33147
- MEDIUMCVE-2025-36084
- MEDIUMCVE-2025-36591
- MEDIUMCVE-2026-102824PoC
- LOWCVE-2026-18104
- MEDIUMCVE-2026-18153
- LOWCVE-2026-81438
Related by shared AI tags and CWE weakness class. Browse the full archive.