PT-2026-92424 · Http4S · Http4S
CVE-2026-69206
·
Published
2026-09-15
·
Updated
2026-09-16
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Http4s versions prior to 0.23.35
Http4s versions prior to 1.0.0-M47
Description
DigestAuth replay protection records
lastNc plus one instead of the highest nonce-count value it has accepted. When a legitimate client sends noncontiguous nc values due to parallel or retried requests, the stored counter remains below the accepted maximum. This allows a passive observer to replay a captured Authorization header multiple times to execute authenticated requests, including state-changing operations, as the captured user. This defeats the core replay protection that Digest authentication provides over Basic authentication.Recommendations
Update to version 0.23.35.
Update to version 1.0.0-M47.
Deploy the application over TLS to prevent requests from being captured.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Http4S