PT-2026-92424 · Http4S · Http4S

CVE-2026-69206

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Http4s versions prior to 0.23.35 Http4s versions prior to 1.0.0-M47
Description DigestAuth replay protection records lastNc plus one instead of the highest nonce-count value it has accepted. When a legitimate client sends noncontiguous nc values due to parallel or retried requests, the stored counter remains below the accepted maximum. This allows a passive observer to replay a captured Authorization header multiple times to execute authenticated requests, including state-changing operations, as the captured user. This defeats the core replay protection that Digest authentication provides over Basic authentication.
Recommendations Update to version 0.23.35. Update to version 1.0.0-M47. Deploy the application over TLS to prevent requests from being captured.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-69206
GHSA-9XWW-74XV-GJFP

Affected Products

Http4S